MILITARY CRYPTANALYSIS 






PAST I — MONQALPHABETIC SUBSTITUTION SYSTEMS 






i 



WILLIAM P. PRIEDMN 



Principal Cryptanalyst 



Prepared under the direction of the Chief Signal Officer. 
Declassified and approved for release by NSA on 12-23-2013 pursuant to E.O. 135261 




REF ID : A64644 



1 




30 April 1959 




Paul S. Willard 
Colonel; AGC 
Adjutant GenersLl 






< 




MILITARY ORYPTAf«AI^YSTS. PART I 
Monoalphabeiic Substitution Systems 



Section Paragraphs Pago 



I. 


Introductory remarks 


• • • • 3. 


- 3 


1 


11. 


Fundamental principles 


• • • • 4 


- 8 


10 


III. 


Frequency distr Ibuti oxas 


. . . . 9 


- 11 


16 


IV. 


Fundamental uses of the monoliteral frequency 
distribution 


32 


- 16 


24 


V. 


Mono literal substitution with standard cipher 
alphabets 


17 


- 22 


31 


VI. 


Monoliteral substitution with mixed cipher 

alx^habets 


23 


- 34 


49 


VII. 


Polyliteral substitution with mono- equivalent 
cipher alphabets 


. . . . 58 


- 36 


73 


VIII. 


Polyliteral substitution with poly-equivalent 
cipher alphabets 


37 


- 40 


77 


IX. 


Polygraphic substitution systems 


41 


- 46 


88 


X. 


Concluding remarks 


. . . . 47 


- 80 


120 



» 









* 



APPENDIX 



Table No. Page 

f 

1-A Absolute frequencies of letters apjjearing in five 
sots of Government plain- text telegrams, each 
set containing 10,000 letters. Arranged al- 
phabetically 127 

1-E Absolute frequencies of letters appearing in five 
sots of Governijent plrin-text telegrams, each 
set containing 10,000 letters. Arranged ac- 
cording to frequency 120 

1-C Absolute frequencies of vowels, high frequency con- 
sonants, mediiim frequency conson'^nts, and low 
frequency consonants appearing in five sets of 
Government plain- text telegrams, each set con- 



taining 10,000 letters 128 

2-A Absolute frequency of letters appearing in the com- 
bined five sets of messages totalling 80,000 let- 
ters, arranged alphabetically 127 

2-B Absolute frequency of letters ajjps'^ring in the com- 
bined five sets of messages totalling 80,000 let- 
ters, arranged according to froqtiency 129 

2-C Absolute frequency of vowels, high frequency conso- ) 

nants, medium frequency consonants, and low fre- 
quency consonants appearing in the combined five 
sets of messages totalling 80,000 letters 129 



CONriDENTIAL : 



KEF ID:A64644 



Table Ho. Page 

2-D Absolute frequencies of letters as initial letters 
of 10,000 wor'is fount in G jvernmunt plain- text 
telegrams, (l) arranged alphabetically, an^ 

(2) according to absolute frequencies 129 

2-E Absolute frequencies of letters as final letters of 
10,000 v/ords found in Government plain-text 
telegrams, (l) arranged alphabetically, and 

(2) according to absolute frequencies ISO 

5. Relative frequencies of letters ■ppeorinr; in 3,000 
letters based upon Table 2, (1) arranged al- 
phabetically, (2) according t-> absolute fre- 
quency, (S) vowels, (4) high frequency con- 
sonants, (5) medium frequency cunsonants , and 



(6) low frequency c'^nsonants 130-151 

4. Frequency distribution for 10,QOO letters of lit- 

erary English, (l) arranged alphabetically, and 

(2) according to absolute frequencies 131 

5. Frequency distribution for 10,000 letters of tele- 

graphic English, (l) arranged alphabetically, 

and (2) according to absolute frequencies 131 

6. P'requency distribution of digraphs, based on 50,000 

letters of Government plain- text telcgr.-ans , re- 
duced to 5,000 digraphs 132 

7-A The 438 different digraphs of Table 6 arranged ac- 
cording to their absolute frequencies 1S3-134 



7-B The 18 digraphs composing 2'i'^' of the digraphs in 

Table 6. Arranged alphabetically according to 
their initial letters, (1) and according to 
their fin<al letters (2) and according to their 

absolute frequencies 13'i 

7-C The 53 digraphs composing 50^ of the digraphs in 

Table 6. Arranged alphabetically a>^cording to 
their initial letters, (l) and according t" 
their final letters (2) and according to their 

absolute frequencies 136 

7-D The 117 digraphs ccmpc'Sing 75=? of the digraphs in 
Table 6. Arranged alphcabetically according to 
their initial letters, (1) and according to 
their final letters (2) and according to their 



absj>lute frequencies 137-138 

7-E A.11 the 433 digraphs of Table 6, arranged first al- 

phabetically according to their initial letters 
and then alphabeticrally according to their final 

letters 158 

(See Table 6. Read across the rows) 152 

8. The 438 different digraphs of Table 6 arranged first 

alphabetically according to their initial letters, 
and then according tc their absolute frequencies 

under each initial letter 159-141 

9-A The 438 different digraphs of Table 6 arranged first 
alphabetically according to their final letters 
and then according to their absolute frequencies.. 142-144 



i 






ir 






y 



i 







REF ID:A64644 



Tahiti N'j . Pag^ 



9-B The 18 digraphs composing 2'^% the KOOO digraphs 
of Table 6, arranged alphabetically according 
to thoir final letters, (l) and according to 
thejr initial letters, (2) and according to 

^ their absolute frequencies..... 14*^ 

9-C The 53 digraphs composing 50^ of the 5000 digraphs 
of Table G, arranged alphabetically according 
* to thoir final letters, (l) and according to 

their initial letters, (2) and according to 

their absolute frequencies 146 

9-D The 117 digraphs composing 75*? of the 5000 digraphs 
of Table 6, arranged alphabetically according 
to their final letters, (l) and according t«. 

thoir initial letters, 147 

(2) and according to their nbsilute frequencies... 148 

9--E All the 438 different digraphs '■•f Table 6 arranged 
alphabetically first acc 'rcling to thoir final 
letters and then according to their initial let- 
ters ; 148 

(See Table 6. Read duvm the columns) 132 

10- The 56 trigraphs appearing 100 or more times in the 

50,000 letters of government plain-text tele- 
jr grams — 

-A Arranged according to their absolute frequencies....... 149 

-B Arranged first alphabetically according to their 
initial letters and then according to their 

absolute frequencies 150 

-C Arranged first alphabetically according to their 
central letters and then according to their 

absolute frequencies.. 151 

-D Arranged first alphabetically according to their 
final letters and then according to their 

absolute frequencies 152 

11- The 54 tetragraphe appearing 50 or more times in 

the 50,000 letters of government plain-text 
telegrams — 

-A Arranged according to their absolute frequencies 153 

-B Arranged first alphabetically according to their 
initial letters and then according to their 

absolute frequencies 154 

-C Arranged first alpliabetioally according to their 
i second letters and then according to their 

absolute frequencies 155 

-D Arranged first alphabetically according to their 
^ third letters and then according to thoir 

absolute frequencies 156 

-E Arranged first alphabetically according to their 
final letters and then according to their 

absolute frequencies 157 

12. Average and mean lengths of vrords. 158 



REF ID : A64644 



EKRA.IA 



Page 


Paragraph 


Line 


Now Reads ~ 


Correction — 


3 


2b 


Last line 


"—more e 25 >eoially" 


"—more especially — " 


4 


2o 


5 


"—light breaks and-" 


"—light breaks through. 










and—" 


4 


Footnote 
2nd Par. 


2 


"—into casual" 


" — into causal" 


7 


2f 


2 


" — omental jarrs— " 


"—mental jars — " 


X7 


9o 


6 


"111 in Fig. 2 " 


"... in Fig. 2" 


17 


9e 


4 


"totaling approximate- 


"totaUing 10,000" 








ly 10,000" 


22 


Tables 4,5 


2nd Title 


" — according to rola- 


"—according to fre- 






line 


tiTe frequency" 


quency" 


24 


Footnote 


Last line 


"—a bar-distribution" 


"—a distribution" 


26 


13d 


13 


"—between 0 and 8—" 


"—between 0 and 3 — " 


28 


14b 


9 


"—to certain language""— to certain languages" 


35 


18o 


IlLddle of j 


5th group in 2nd line ' 








Page 


of cryptogram - "GXUUT" should read - "GCTUT" 


35 


18o 


Fig. 7 


Tally over letter D should be omitted. 


36 


18e 1 


4,7,12,13 


"—three letters—" 


"—four letters — " 


38 


19a(2) 


7 


"—to note where—" 


" — to note whether—" 


38 


19a(2) 


9 


"— quenoy letters--" 


"—quenoy consonants — " 


38 


19a(4) 


6 


"—to curve C" 


"—to curve R" 


39 


19a(6) 


4 


thus;" 


"Fp,Gp,Hp, ... thus;" 


40 


19b(4) 


Fig.lOd 


Add one more tally over letter X. 


42 


20a (4) 


13 


"—first ^ letters" 


"—first ^ letters" 


47 


21b 


7 


"its oxtant" 


"its extent" 


47 


21c 


17 


"— K Z G H " 


"— K Z G D " 


51 


25a 


5 


"Table 1" 


"Tablo 6" 


51 


25a 


7 


"—that 546" 


"—that 428" 


52 


26o 


• 6 


" — allow one space — " 


" — allow tvro spaces — " 


54 


27e 


4 


" — upper half—" 


"—loft half—" 


54 


27e 


5,6 


"—directly opposite" 


" — directly above" 


54 


27e 


6 


Icwcr half" 


"—right half" 


54 


27e 


8 


"—directly above" 


"—directly to tho 










left of" 


"56 


27f 


9 


Under "Digraphs based 
on Suffixes"— "DF,DZ , " 


"DT, DZ" 


56 


27g 


5 


"DF appears 6 times" 


"DP appears five times" 


57 


28a 


Last lino 


"filed in—" 


"fined in—"" 


58 


28b 


4th lino 










from end 


"—as does also—" 


"—as do also—" 


58 


29a 


4 


"—to Table 11" 


"—to Tablo 6" 


58 


29a 


7 


Correct figures to road: "41,37,35,27,17,13,13, 










12,12,11" 


59 


29a 


3rd line 
from bottom 


"—in Table 11" 


"—in Table 6" 


60 


29a 


Top of page 


Correct figures to read; "7,5,13,25,37,17,5,59" 


60 


29a ■ 


6 


"SVe— UIp" 


"5Vo*=AIp" 


60 


29a 


7 


"ISo»»AUp" 


"ISo=U^" 




REF ID:A64644 



Pago 


Paragraph 


Line 


Nofw Reads -- 


Correction — 


60 


29a 


9 


"—is almost" 


" — is more than" 


60 


29b 


8 


"—viz., TIONq" 


"—viz., TION^" 
should be E instead of Z 


65 


31o 


2 


Last letter in line 2 s 


65 


1 31d 


9 


" — ^this keyword six" 


"—this keyword five" 




32o(5) 


5 


"Table 1^" 


"Table 10 A" 


^68 


32e 


9,10 


Delete sentence begirm: 


.ng; "In this connection 


73 


35b 


5,6 


Mr* 1? *7 M 

fc M 7T 


Mr* P 7 M 

1 ••• 4l 

Wi W H 


75 


36a 


13 


"P P y y e m n s h y" 


"P p y y o m n s n y" 


75 


36a 


14 


"n s ^ e u s— " 


"n s p e n s— " 


75 


36a 


16 


End of line: "t e 1" 


"t e i" “ 


76 


36b 


4 


End of line; "55 52" 


"55 42" 


76 


36b 


5 


"90 66 77 ^ 33 8T~65» 


"93 66 77 ^ 33 84 


79 


38o 


2 


" — for example 330" 


’CTfor example 494" 


79 


38o 


3 


"—composed of i'65" 


"—composed of S'47" 


83 


40a 


12 


"—row and -indicators" 

A 


"—row and column indi- 
cators" 


84 


40b 


11 i 


"Only 3" 


"Only 4" 


86 


41o 


7 


"— XYo“and AC,," 


"— XYo and „ 

"—whole result. " 


86 


41o 


9 


" - -whol 0 re suit . " 


92 


44c (4) 


4th lino 
from end 


"J. ^ QC — " •• , 


"J. ^ QC — " 


94 


44o(8) 


5 


"—Sections 3 and- 2" 


"«-SGotions 3 and 4" 


106 


46d(l) 


7 


"—in Pig. 25" ~ 


"—in Pig. 25a" ■“ 


108 I 


46o(l) 


8,11 


"XCPTOTCXOT— " 


"XCPTOTCXOT':^ 


108 1 


46o(2) 


footnote 


"iSoo Par. 48c" 


"-J-Seo Par. 44c" 


111 


46o 


3,15 


"— CY NO TE^^ 


"— CY NO ty':::::::'”' 


119 


46h 


12 


"other devined— " 


"other divined—" 


121 


47o 


8 


"envelop"^’ 


"envelope" 


6!f67 


32o(5) 


9 


"Table ]^" 


"Table 11 A" 




REF ID : A64644 

SECTIOIJ I. 

INTRODUGTOHY FEBMARKS 

Paragraph 



Scope of this text 1 

f Mental equipment necessary for cryptanalytic work 2 

Validity of results of cryptanalysis 3 



1. Scope of this text. - a. It is assumed that the student has 
studied the two preceding texts forming part of this series, viz., Special 
Text No, 165, Elementary Military Cryptography, and Special Text No, 166, 
Advanced Military Cryptography, The latter texts deal exclusively with 
cryptography as defined therein; that is, with the various types of ciphers 
and codes, their principles of construction, and their employment in 
crypto graphing and decrypt o graphing messages. Particular emphasis v/as 
placed upon such means and methods as are practicable for military usage. 

It is also assumed that the student has firmly in mind the technically 
precise, special nomenclature employed in those texts, for the terms and 
definitions therein will all be used in the present text, with essientially 
the same significances. If this is not the case, it is recommended that 
the student review his preceding work, in order to regain a familiarity 
with the specific meanings assigned to the terms used therein. There will 
be no opportunity herein to repeat this information and unless he under- 
stands clearly the significance of the terms employed, his progress will 
be retarded. 

b. This text constitutes the first of a series of texts on crypt- 
analysis. Although most of the information contained herein is applicable 
to cryptograms of whatever type and source, special emphasis will be laid 
upon 'the principles and methods of solving military cryptograms. Except 
for an introductory discussion of fundamental principles underlying the 
science of cryptanalytics , this first text in the series will deal solely 
with the principles and methods for the analysis of monalphabetic substi- 
tution ciphers. Even with this limitation it will be impossible to dis- 
cuss all the many variations of this one type, but with a firm grasp upon 
the general principles no difficultie.s should be experienced with, any 
variations that may be encountered. 

This and some of the succeeding texts will deal only with ele- 
mentary types of cipher systems not because they may bo encountered in 
military operations but because their study is essential to an understand- 
ing of the principles underlying the solution of the modern, very much 
more complex types of ciphers and codes that are employed by the larger 
governments today in the conduct of their military affairs in time of war. 

d. All of this series of texts will deal only with the solution of 
visible secret writing. At some future date texts dealing with the solu- 
tion of invisible secret writing, and with secret signalling systems may 
be prepared. 



i 



REF ID:A64644 



- 2 - 

2. iJontal oquipraont mcossary for cryptanalytic worlc. - a. Captain 
Parkor Hitt, in tho first Unitod Statos Army manual"^ dealing vdth cryp- 
tography> opens tho first ch.-ptor of bis valuable troatiso with tho follow- 
ing sontoncos 

"Success in dealing with unlcnown ciphers is measured 
' by these four things in the order named, perseverance, 

careful methods of analysis, intuition, luck." 

These words are as true today as they were then. There is no royal road 
to success in the solution of cryptograms. Hitt goes on to sayi 

"Cipher work -vill have little permanent attraction 
for one who expects results at once, without labor, for 
there is a vast amount of purely routine labor in the 
preparation of frequency tables, the rearrangement of 
ciphers for examination, and the trial and fitting of 
letter to latter before the message begins to appear." 

The present author deems it advisable to add that the kind of work in- * 
volved in solving cryptograms is not at all similar to that involved in 
solving "cross-word puzzles," for example. The wide vogue the latter have 
had and continue to have is due to the appeal they make to the quite com- 
mon instinct for mysteries of one sort or another; but in solving a cross- 
word puzzle there is usually no necessity for performing any preliminary 
labor, and palpable results become evident after the first minute or two 
of attention. This successful start spurs the cross-word "addict" on to 
complete the solution, which rarely requires more than an hour's time. 
Furthermore, cross-word puzzles are all alike in basic principle and once 
understood, there is no more to learn. Skill comes largely from the ombel- 
lishraent of one's vocabulary, though, to be sure, constant practice and 
exercise of the imagination contribute to the ease and rapidity v/ith which 
solutions are generally reacnod. In solving cryptograms, however, many 
principles must bo learned, for there are many diffe -ont systoms, of vary- 
ing degrees of complexity. Sven somo of the simpler vrrioties require the 
preparation of tabulations of one sort or another, which many people find 
irksome; moreover, it is only toward the very close of the solution that 
results in the form of intelligible text become evident. Often, indeed, 
the student v/ill not even know whether he is on the right track until he 
has performed a large amount of preliminary "spade work" involving many 
hours of labor. Thus, without at least a willingness to pursue a fair 
amount of theoretical study, and a more than average amount of patience 
and perseverance , little skill and experience can bo gained in the rather 



Hitt, Capt. Parker. Manual for the Solution of Military Ciphers . Army 
Service Schools Press, Fort Leavenworth, Kansas, 1916. 2d Edition, 1918 
(Both out of print) 



REF ID : A64644 



c 



p 



c 






- 3 - 

difficult ait of cryptanalysis. General Givierge's remarks in this con- 
nection are of interest. He says^> 

"The cryptanalyst's attitude must be that of t/illiam 
the Silent: No need to hope in order to undertake, nor 

to succeed in order to persevere." 

b. As regards Hitt's reference to careful methods of analysis, be- 
fore one can be said to be a cryptanalyst worthy of the name it is neces- 
sary that one should have first a sound knov/ledge of the basic principles 
of cryptanalysis, and secondly a long, varied, and active practical ex- 
perience in the successful application of those principles. It is not 
sufficient to have road treatises on this subject. One month's actual 
practice in solution is worth a whole year's mere reading of theoretical 
principles. An exceedingly importajit element of success in solving the 
more intricate ciphers is the possession of the rather unusual mental 
faculty designated in general terms as the power of inductive and deduc- 
tive reasoning. Probably this is an inherited rather than an acquired 
faculty; the best sort of training for its emergence, if latent in the 
individual, and for its development is the study of the natural sciences, 
such as chemistry, physics, biology, geology, and the like. Other sciences 
such as linguistics and philology are also excellent. Aptitude in mathe- 
matics is quite important, more expecially in the solution of ciphers than 
of codes. 

c. An active imagination, o" perhaps v/hat Hitt and other v/riters 
call intuition , is essential, but mere imagination uncontrolled by a 
judicious spirit will more often be a hindrance than a help. In prac- 
tical cryptanalysis the imaginative or intuitive faculties must, in other 
words, be guided by good judgment, by practical experience, and by as 
thorough a knowledge of the general situation or extraneous circumstances 
that led to the sending of the cryptogram as is possible to obtain. In 
this respect the many cryptograms exchanged between correspondents whose 
identities and general affairs, commercial, social, or political, are 
known are far more readily solved than are isolated cryptograms exchanged 
between unknown correspondents, dealing vri.th unknoim subjects. It is ob- 
vious that in tho former case thore are good data upon v/hich the intuitive 
pov/ers of the cryptanalyst can be brought to bear, whereas in the latter 
case no such data are available. Consequently, in the absence of such 
data, no matter how good the imagination and intuition of tho cryptanalyst, 
these powers are of no particular sorvico to him. Some writers, however, 
regard the intuitive spirit as valuable from still another viewpoint, as 
may be noted in the following;^ 

^ Givierge, General Marcel. Cours de Crypt ographie , Paris, 1925. ( P.301) 



Lange et Soudart. Traite de Crypt ographie. Librairie Felix Alcan, 
Paris, 1925. 




KE^“ ID : A64644 

"Intuition, like a flash of li-^htning, lasts only 
for a second. It generally coiaes v/hen one is tormented 
by a difficult decipherment and v/hen one reviews in his 
mind the fruitless experiments already tried. Suddenly 
the light breaks and one finds after a few minutes v/hat 
previous days of, labor were unable to reveal." 

This, too, is true, but unfortunately there is no v/ay in which the intui- 
tion may be summoned at will, when it is most needed.^ There are certain 

^ The following extracts are of interest in this connection: 

"The fact that the scientific investigator works 
50 per cent of his time by non-rational moans is, it 
seems, quite insufficiently recognized. Thcro is with- 
out the least doubt an instinct for research, and often 
tho most successful investigators of nature are quite 
unable te give an account of their reasons for doing 
such and such an oxporimont , or for placing side by side 
two apparently unrelated facts. Again, one of tho most 
salient traits in tho character of tho successful scien- 
tific v/orker is tho capacity for knowing that a point is 
proved when it would not appear to bo proved to an out- 
side intelligence functioning in a purely rational man- 
ner; thus tho investigator feels that somo proposition 
is true, and proceeds at once to tho next sot of oxpori- 
monts without waiting and v/asting time in tho elaboration 

of tho formal proof of tho point which heavier minds would ^ 

need. Questionless such a scientific intuition may and 
^oos sometimes load investigators astray, but it is quite 

certain that if they did not widely make use of it, they a 

v/ould not get a quarter as far as they do. Experiments 
confirm each other, and a false step is usually soon dis- 
covered. And not only by this partial replacement of 
reason by intuition does the work of science go on, but 
also to the born scientific worker - and emphatically they 
cannot be made - the structure of the method of research 
is as it were given, he cannot explain it to you, though 
he may be brought to agree a postiori to a formal logical 
presentation of the way the method works." - Excerpt from 
Needham, Joseph. "The Sceptical Biologist," page 79. 

London, 1929. 

"The essence of scientific method, quite simply, is 
to try to see how data arrange themselves into casual con- 
figurations. Scientific problems are solved by collect- ^ 

ing data and by 'thinking about them all the time.' We 
need to look at strange things until, by the appearance 
of known configurations, they seem familio.r, and to look 

at familiar things until we see novel configurations which • 



s= 



REF ID:A64644 



- 5 - 

authors who regard as indispensable the possession of a somewhat rare 5 
rather mysterious faculty that they designate by the word "flair," or 
by the expression "cipher brains." Even so excellent an authority as 
General Givierge,^ in referring to this mental facility, uses the fol- 
lowing words s " ... and this aptitude of mind vfhich some authors con- 
sider a special gift, and which they call intuition, or even, in its 
highest manifestation, clairvoyance ... although the present author 
believes a special .aptitude for the work is essential to cryptanalytic 
success, he is sure thorc is nothing mysterious about the matter at all. 
Special aptitude is prerequisite to success in all fields of endor.vor. 
There are, for example, thousands of physicists, hundreds of excellent 
ones, but only a h-andful of world -wide fame. Should it bo said, then, 
that a physicist who has achiovod very not. able succoss in his field has 
done so bocauso ho is the fortunate possessor of a mysterious faculty? 
That ho is fortunate in possessing a special aptitude for his subject is 
granted, but that there is anything mysterious about it, part.aking of 
the nature of clairvoy.anco (if, indeed, the latter is a reality ) is not 
granted. ViHiila the ultimate nature of any mental process seems to bo 
•as complete .a mystery today as it has over boon, the present author 
would like to see the superfici.al veil of mystery removed from a sub- 
ject that has bean shrouded in mystery from even before the tliddle Ages 
down to our own times. (The principal and easily understandable reason 
for this is that governments have always closely guarded cryptographic 
secrets and anything so guarded soon becomes "mysterious.") He would, 
rather, have the student approach the subject as he might approach any 
other science that can stand on its own merits with other sciences, be- 
cause cryptanalytics , like other sciences, has a practical importance in 
human affairs. It presents to the inquiring mind an interest in its own 



make them appear strange. ’Ve must look at events until 
they become luminous. That is scientific method ... . 
Insight is the touchstone ... . The application of in- 
sight as the touchstone of method enables us to evaluate 
properly the role of imagination in scientific method. 

The scientific process is akin to the artistic process, 
it is a process of selecting out those elemonts of ex- 
perience which fit together and recombining them in the 
mind. Much of this kind of research is simply a cease- 
less mulling over, and even the physical scientist, has 
considerable need of an armchair." "Our view of scien- 
tific method as a struggle to obtain insight forces the 
admission that science is half art." "Insight is the 
unknown quantity which has eluded students of scientific 
method." - Excerpts from an article entitled "Insight and 
Scientific Method" by V/illard Waller, in The iunerican 
Journal of Sociology . Vol. XL, 1934. 




1 



Loc. cit., p. 302 



ID : A64644 



ri’^ht as a branch of knowledge; it, too, holds forth many difficulties and 
disappointments, and these are all the more keenly felt when the nature of 
these difficulties is not understood by those unfamiliar with the special 
circumstances that very often are the real factors that led to success in 
other oases. Finally, just as in the other sciences wherein many men labor 
long and earnestly for the true satisfaction and pleasure that comes from 
work v/ell-done, so the mental pleasure that the successful cryptanalyst 
derives from his accomplishments is very often the only reward for much of 
the drudgery that he must do in his daily work. Givierge's words in this 
connection are well worth quoting. Ho says (p. 301) i 

"Some studies v/ill last for years before bearing 
fruit. In the case of others, cryptanalysts undertaking 
thorn never got any result. But, for a cryptanalyst who 
likes the work, the joy of discovorios effaces the memory 
of his hours of doubt and impatience.” 

d. With his usual daft touch, Hitt says of the olemont of luck, as 
regards the rolo it plays in analysis; 

"As to luck, there is the old miners' proverb 'Gold 
is v;here you find it'.” 

Tho cryptanalyst is lucky ’.vhon ono of the corrospondonts whose ciphers ho 
is studying makes a blunder that gives the necessary clue; or when ho finds 
two cryptograms identical in text but in different keys in tho same system; 
or v/hon ho finds tv/o cryptograms identical in text but in different systems, 
and so on. The oloraent of luck is thoro, to be sure, but the cryptanalyst 
must be on the alert if he is to profit by these lucky "breaks." 

e. If the present author were asked to state, in view of the progress 
in the field since 1916, what elements might be added to the four ingredi- 
ents Hitt thought essential to cryptanalytic success, he v/ould be inclined 
to mention the following; 

(1) A broad, general education, embodying interests 
covering as many fields of practical knowledge as possible. 

This is useful because the cryptanalyst is often called 
upon to solve messages dealing with the most varied of 
human activities, and the more he knows about these ac- 
tivities, the easier his task. 

( 2 ) Access to a large library of current literature 
and wide and direct contacts with sources of collateral 
information. These often afford clues as to the contents 
of specific massages. For example, to be able instantly 
to have at his disposal a newspaper report or a personal 
report of events described or referred to in a message 
under investigation goes a long way toward simplifying or 
facilitating solution. Government cryptanalysts are some- 
times fortunately situated in this respect, especially 
whore various agencies work in hn.rmony. 



REF ID:A64644 



- 7 - 

(3) Proper coordination of effort. This includes 
the organization of cryptanalytic personnel into har- 
monious, efficient teams of cooperating individuals. 

(4) Under mental equipment he would also include 

« the faculty of being able to concentrate on a problem 

for rather long periods of time, without distraction, 
nervous irritability, and impatience. The strain under 
which cryptanalytic studies are necessarily conducted 
is quite severe and too long-continued application has 
the effect of draining nervous energy to an unwholesome 
degree, so that a word or tv/o of caution may not hero 
be out of place. One should continue at work only so 
long as a peaceful, calm spirit prevails, whether the 
work is fruitful or not. But just as soon as the mind 
becomes weariod v/ith tho exertion, or just as soon as a 
fooling of hopelessness or mental fatigue intorvones, 
it is better to stop completely and turn to other ac- 
tivities, rest, or play. It is essential to .‘omark 
that systematization and orderliness of work are aids 
in reducing nervous tension and irritability. On this 
account it is better to take the time to prepare the 
data carefully, rewrite the text if necessary, and so 
on, rather than work with slipshod, incomplete, or im- 
properly arranged material. 

(5) A retentive memory is an important asset to 

^ cryptanalytic skill, especially in the solution of codes. 

The ability to remember individual groups, their ap- 
proximate locations in other messages, the associations 
they form with other groups, their peculiarities and 
similarities saves much wear and tear of the mental 
machinery, as well as much time in looking up these 
groups in indexes, 

f. It may be advisable to add a word or tv/o at this point to prepare 
the student to expect slight mental jarrs and tensions which will almost 
inevitably come to him in the conscientious study of this and the subse- 
quent texts. The present author is well aware of the complaint of students 
that authors of texts on cryptanalysis baso much of their explanation upon 
their fore-knowledge of tho "answer”- which the student does not know while 
he is attempting to follow tho solution with an unbiased mind. They com- 
^ plain too that those authors use such oxprossions as "obviously", "natural- 

ly", "of course", "It is evident that", and so on, v/hon the circumstances 
seem not at all to warrant their use, Thoro is no question but that this 
sort of troatraont is apt to discourage tho student, especially when tho 
* point olucidatod becomes clear to him only after many hours labor, whereas, 

according to the book, the author noted the weak spot' at the first moment's 
inspection. The present author can only promise to try to avoid making the 
steps appear to be much more simple than they really are, and to suppress 



REF ID:A64644 



- 8 - 

glaring instances of unjustifiable "jumping at conclusions'*. At the same 
time he must indicate that for pedagogical reasons in many cases a message 
has been consciously "manipulated" so as to allow certain principles to 
become more obvious in the illustrative examples than they ever are in 
practical work. During the course of some of the explanations attention 
will even be directed to cases of unjustified inforences. Furthermore, of 
the student who is quick in observation and deduction, the author will only 
ask that he bear in iiiind that if the elucidation of certain principles 
seems prolix and occupies more space than necessary, this is occasioned by 
the author's desire to carry tho explanation forward in very short, oasily- 
comprohonded , and plainly-described stops, for the benefit of students who 
are perhaps a bit slower to grasp but who, onco they understand, aro able 
to retain and apply principles slowly learned just as woll, if not bettor 
than tho students v/ho loam more quickly. 

3. Validity of results of cryptanalysis. - Valid, or authentic crypt- 
analytic solutions cannot and do not represent "opinions" of tho crypt- 
analyst. They are valid only so far as they are wholly objective, and are 
susceptible of demonstration and proof, employing authentic, objective 
methods. It should hardly be necessary (but an attitude frequently en- 
countered among laymen makes it advisable) to indicate that the validity 
of the results achieved by any serious cryptanalytic studies on authentic 
material rests upon the same sure foundations and are reached by the same 
general steps as the results achieved by any other scientific studies; viz., 
observation, hypothesis, deduction and induction, and confirmatory experi- 
ment. Implied in the latter is the possibility that two or more qualified 
investigators, each working independently upon the same material, will 
achieve identical (or practically identical) results. Occasionally a 
pseudo-cryptanalyst offers "solutions" v;hich cannot withstand such tests; 
a second, unbiased, investigator working independently either cannot con- 
sistently apply the methods alleged to have been applied by the pseudo- 
cryptanalyst, or else, if he can apply them at all, the results (plain- 
taxt translations) are far different in the tv/o cases. The reason for 
this is that in such cases it is generally found that the "methods" are 
not clear-cut, straight fonvard or mathematical in character. Instead, 
they often involve the making of judgments on matters too tenuous to 
measure, weigh, or otherwise subject to careful scrutiny. In such cases, 
the conclusion to v/hich the unprejudiced observer is forced to come is 
that the alleged "solution" obtained by the first investigator, the pseudo- 
cryptanalyst, is purely subjective. In nearly ail cases where this has 
happened (and they occur from time to time) there has been uncovered 
nothing which can in any way be used to impugn the integrity of the 
pseudo- crypt analyst . The worst that can bo said of him is that he has 
become a victim of a special or peculiar form of self-delusion, and that 
his desire to solve tho problom, usually in accord with some previously- 
formed opinion, or notion, has over-balanced , or undermined, his judgment 



REF ID : A64644 



- 9 - 

and good sense ^ 



^ Specific reference can be made to the following typical "case histo- 
ries": 

Donnelly, Ignatius, The Great Cryptogram . Chicago, 188B. 

Owen, Orville W, , Sir Francis Bacon's Cipher Story . Detroit, 1895. 

Gallup, Elizabeth Wells, Francis Bacon*s Biliteral Cipher . Detroit, 1900. 
Margoliouth, D. S,, The Homer of Aristotle . Oxford, 1923. 

Newbold, William Romaine, The Cipher of Roger Bacon . Philadelphia, 1928. 
(For a scholarly and complete demolition of Professor Newbold 's 
work, see an article entitled " Roger Bacon and the Voynich MS ", by 
John M. Ivlanly, in Speculum . Vol. VI, No. 3, July 1931.) 

Arensberg, ’/alter Conrad, The Cryptography of Shakespeare . Los Angeles, 
1922. 

The Shakespearean Mystery . Pittsburgh, 1928. 

The Baconian Keys . Pittsburgh, 1928. 

Feely, Joseph Martin, The Shakespearean Cypher . Rochestor, N. Y. , 1931. 
Deciphering Shakespeare . Rochester, N. Y. , 1934. 









ID:A64644 



5ECTI0H II 

FUlJJAi/fflOTAL K-^IilCIPLES 



Paragraph 



The four basic operations in cryptanalysis 4 

The determination of the language employed 5 

The determination of the general system 6 

The reconstruction of the specific key 7 

The reconstruction of the plain text. ....... 8 



4. The four basic operations in cryptanalysis. - a. The solution 
of practically every cryptogram involves four fundamental operations or 
steps « 

(1) The determination of the language employed in 
the plain-text version. 

(2) The determination of the general system of 
cryptography employed, 

(3) The reconstruction of the specific key in the 
case of a cipher system, or the reconstruction, partial 
or complete, of the code book, in the case of a code 
system; or both, in the case of an enciphered code system. 

(4) The reconstruction or establishment of the plain 

text. 

b. These operations will be taken up in the order in which they are 
given above and in which they usually are performed in the solution of 
cryptograms, although occasionally tho second stop may precedo the first. 

5. Tho determination of tho language employed. - a. There is not 
much that need be said with respect to this operation except that the de- 
termination of the language employed seldom comes into question in the 
case of studies made of the cryptograms of an organized enemy. By this is 
meant that during war time the enemy is of course known, and it follows, 
therefore, that the language he employs in his messages will almost cer- 
tainly be his native or mother tongue. Only occasionally nowadays is this 
rule broken. Fomorly it often happened, or it might have indeed been the 
general rule, that the language used in diplomatic correspondence was not 
the mother tongue, but French. In isolated instances during tho World War, 
tho Gormans usod English when their own language could for ono reason or 
another not be employed. For example, for a yoar or two before the entry 
of tho United States into that war, during tho time hraorica was neutral 

and the German Government maintained its embassy in Washington, the messages 
exchanged between tho Foreign Office in Berlin and tho Embassy in Washing- 
ton wore cryptographed in English, and a copy of tho code usod was deposited 
with the Department of State and our censor. Another instance is found in 
the case of certain Hindu conspirators who were associated with and partially 
financed by the German Government in 1915 and 1916; they employed English as 



REF ID:A64644 

-li- 




the language of their cryptographic messages. nccssionaH-ly the crypto- 
grams of enemy agents may be In a language different from that of the 
enemy. But in general these t:re, as has been said, isolated instances; 
as a rule, the language used in cr’^ptograms exchanged be ween members of 
large organisations is the mother tongue of the correspondents, '"‘here 
this is not the case, that is, when cryptograms of unknown origin must 
be studied, the cryptanalyst looks for any indications on the cryptograms 
themselves which msy lead to a conclusion as to the language employed. 
Address, signature, and plain-1 angijage words in the preamble or in the 
body of tho text all come undtar careful scrutiny, as '■/'cll as all extran- 
eous circumstances connected ’-'ith the manner in which the cryptograms 
were obtained, the person on v'hom they were found, or the locale of their 
origin and destination. 

b. In special cases, or under special circumstances a clue to the 
language employed is foimd in the nature and comi)osition of the crypto- 
graphic text itself. For example, if the letters K anti W are entirely 
absent or appear very rarely in massages, it may indicate that tho language 
is Spanish, for these letters arc absent in the alphabet of that language 
and are used only to spell foreign words or names. Thr presence of ac- 
cented letters or letters marked ..'ith special signs of one sort or another, 
peculiar to certain languages, will sometimes indicate the language used. 
The Japanese Ilorse telegraph alphabet and tho Russian iviorse telegraph 
alphabet contain combinations of dots and dashes which are peculiar to 
those alphabets and thus the interception of messages containing those 
special i«orse combinations at once indicates the language involved. 

Finally, there are certain peculiarities of clphrbctic 1 'nguagos 'vhich, 
in certain types of cryptograms (pure transposition) , give duos as to 
the language used. For example, the freouont digraph CH, in German, leads 
to the presence, in cryptograms of the typo mentjoned, of many isolated 
C's and H’s; if this is noted, the cryptogram may be assumed to bo in 
Gorman. 



c_. In some cases it is perfectly possible to perform certain steps 
in cryptanalysis before the language of the cryptogram has been definitely 
determined. Frequency studies, for cxcraplo, may be nado and alalytic 
processes performed without this knowledge, and by a cryptanalyst v'holly 
unfamiliar with the language even if it has b'"cn id'entifiod, or who knov/s 
only enough about the language bo enable him to recognize Valid combina- 
tions of letters, syllables;, or o few common words in that language. He 
may, after this, aall to his assistance a translator who may not be a 
cryptanalyst but who can materially aid in making necessary assumptions 



based upon his ^special knpwledge of tho charactorisi ics of the language 
in question, ^hus, cooperation between cryptanalyst and translator 
results in solution.^ 



I The writer has seen in print statements that "during the Vforld ^Var .... 
decoded messages in Japanese and Russian without knowing a word of either 
language." H© has even heard alleged cryptanalysts m;ik'„ such fantastic 
claims. But to say that it is possible to solve a cryptogrrm in a foreign 
language "without knowing a word of that language" is qaiite a different 
thing from saying that it is possible to do so with only a slight knowledge 
of the language. Tii© absurdity and jjnount of oxagweration contained in the 
former statement \dll soon become obvious to the student. It may be stated 
without cavil that the better tho cryptanalyst's knovdodge of the language, 
the easier is his work. 



REF ID : A64644 



- 12 - 

6. The detemination of the freneral system. - a. Except in the case 
of the more simple types of cryptograms, the determination of the general 
system according to which a given crypto;;ran has been produced is usually 
a difficult, if not the most difficult, stop in its solution. The reason 
for this is not hard to find. 



b. As will become apparent to the student as he proceeds with his 
study, in the final analysis, the solution of every cryptogram involving 
a form of substitution depends upon its reduction to monoalphabetic terms, 
if it is not originally in those terms . This is brue not only of ordinary 
substitution ciphers, but also of combined substitution-transposition 
ciphers, and of enciphered code. If the cryptogram must be reduced to 
monoalphabetic terms, the manner of its accomplishment is either indicated 
by the cryptogram itself, by external or internal phenomena which become 
apparent to the cryptanalyst as he studies the cryptogram. If this is im- 
possible, or too difficult the cryptanalyst must, by one means or another, 
discover how to accomplish this reduction by bringing to bear all the 
special or collateral infonnation he can get from all the sources at his 
comnand. If both these possibilities fail him, there is little left but 
the long, tedious, and often fruitless process of elimination. In the 
case of transposition ciphers of the more complex type, the discovery of 
the basic method is often simply a matter of long and tedious elimination 
of possibilities. For cryptanalysis has unfortunately not yet attained 
and may indeed never attain the precision found today in qualitative 
analysis in chemistry, for example, where the analytic process is absolutely 
clear cut and exact in its dichotomy. A few words in explanation of what 
is meant may not be amiss. TiJhen a chemist seeks to determine the identity 
of an unknown substance, he applies certain specific reagents to the sub- 
stance and in a specific sequence. The first reagent tolls him definitely 
into which of two primary classes the unknown substance falls, say class 
A. He then applies a second tost with another specific reagent, which 
tells him again quite definitely into which of two secondary classes the 
unknown substance falls, and so on, until finally he has reduced the un- 
known substance to its simplest terns and has found out what it is. In 
striking contrast to this situation, cryptanalysis affords exceedingly few 
"reagents" or tests that .nay bo applied to determine positively that a 
given cipher belongs to om or the other of two systems yielding externally 
similar results. And this is v/hat makes the analysis of an isolated, com- 
plex cryptogram so difficult. Note the limiting adjective "isolated" in 
the foregoing sontonco, for it is usod advisedly. It is not often that tho 
general system fails to disclose itself or cannot be discovered by painstak- 
ing investigation wiion there is a groat volume of text accumulating from a 
regular traffic between numerous correspondents in a large organization. 
Sooner or later the system becomes known, either as the result of blunders 
and carelessness on the part of the personnel entrusted with the cryptograph- 
ing of the messages, or the accumulation of text itself makes possible the 
determination of the general system by cryptanalytic studies. But in the 
case of a single or even a few isolated cryptograms concerning which little 
or no information can be gained by the cryptanalyst, he is often unable, 
without a knowledge of, or a shrewd guess as to the general system employed, 
to decompose the heterogeneous text of the cryptogram into homogeneous, 

1 



REF ID : A64644 



- 13 - 

raonoalphabetic text, v/hich is Lhe ultimate and essential step in analysis. 
The only knowledge that the cryptanalyst can bring to his aid in this most 
difficult step is that gained by long experience and practice in the analy- 
sis of many different types of systems. 

c. On account of the complexities surrounding this particular phase 
of cryptanalysis, and because in any scheme of analysis based upon succes- 
sive eliminations of alternatives the analyst can only progress as far as 
the extent of his ovai knowledge of all the possible alternatives will per- 
mit, it is necessary that detailed discussion of the eliminative process 
be postponed until the student has covered most of tae field. For example, 
the student will perhaps vra.nt to know at once hov/ ho can distinguish be- 
tv/een a cryptogram that is in code or enciphered code from one that is in 
cipher. It is at this stage of his studies impracticable to give him any 
helpful indications on his question. In return it may be asked of him 
why he should expect to bo able to do this in the early stagos of his 
studies v/hon often tho oxporionced oxpert cryptanalyst is baffled on the 
same scoro. 



d. Hovortholoss , in lieu of noro precise tests not yet discovered, 
a general guide that may be useful in cryptanalysis will bo built up, stop 
by stop as tho student progresses, in the form of a series of charts com- 
prising what may bo designated ** An Analytical Key For Cryptanalysis " (See 
Par. 50.) It may be of assistance to the student if, as he proceeds, he 
will carefully study the chai'ts and note the place which the particular 
cipher he is solving occupies in the general cryptanalytic panorama. They 
admittedly constitute only very brief outlines, and can therefore be of but 
little direct assistance to him in the analysis of the more complex types 
of ciphers he may encounter later on. So far as they go, however, they 
may be found to be quite useful in the study of elementary cryptanalysis. 

For the experienced cryptanalyst they can serve only as a means of assur- 
ing that no possible step or process is inadvertently overlooked in attempts 
to solve a difficult cipher. 



e. Much of the labor involved in cryptanalytic work, as referred to 
in Par. 2, is connected with this determination of the general system. The 
preparation of the text, its rewriting in different forms, sometimes being 
rewritten in a half dozen ways, tho recording of letters, the establish- 
ment of frequencies of occurrences of letters, comparisons and experiments 
made with known material of similar character, and so on, constitute much 
labor that is most often indispensable, but v/hich sometimes turns out to 
have been v/holly unnecessary, or in vain. In a rocent treatise^ it is 
stated quite boldly that "this work onco done, the determination of tho 
system is often relatively easy." This statement can certainly apply only 
to tho simpler typos of ciphers; it is ontii'oly misleading as regards the 
much more frequently oncountorod complex cryptograms of modern times. 

^ Lange ot Soudart , already cited (pago 106). 



REF ID : A64644 



- 14 - 

7. Tho roconst ruction of tho specific key. - a. Nearly all practical 
cryptographic methods require the use of a specific key to guide, control 
or modify the various steps under the general system. Once the latter has 
been disclosed, discovered, or has otherwise come into tho possession of 
the cryptanalyst, tho noxt step in solution is to determine, if necessary, 
and if possible, the specific key that v;as employed to cryptograph the 
message or messages under examination- This determination may not be in 
complete detail; it may go only so far as to load to a knowledge of tho 
number of alphabets involved in a substitution cipher, or tho number of 
columns involved in a transposition cipher, or that a one-part code has 
been used, in the case of a codo system. But it is often dosir?>.blo to de- 
torraino tho specific key in as coraplcto a form and with ns much detail as 
possible, for this information will vory frequently bo usoful in tho solu- 
tion of subsequent cryptograms exchanged between tho same correspondents, 
since tho nature of tho specific koy in a solved casu may bo expected to 
give clues to tho specific koy in an unsolved case. 

b. Frequently, however, the reconstruction of the key is not a pre- 
requisite to, and does not constitute an absolutely necessary preliminary 
step in the fourth basic operation, the reconstruction or establishment of 
the plain text. In many cases, indeed, the two processes are carried along 
simultaneously, the one assisting the other, until in the final stages both 
have been completed in their entireties. In still other cases the recon- 
struction of the specific key nay succeed instead of precede the reconstruc 
tion of the plain text, and is accomplished purely as a matter of academic 
interest; or the specific key may, in unusual cases, never be reconstructed 

3. The reconstruction of the plain text. - §.. Little need be said 
at this point on this phase of cryptanalysis. The process usually con- 
sists, in the case of substitution ciphers, in the establishment of equiva- 
lency between specific letters of the cipher text and the plain text, lette 
by letter, pair by pair, and so on, depending upon the particular type of 
substitution system involved. In the case of transposition ciphers, the 
process consists in rearranging the dements of the cipher text, letter by 
letter, pair by pair, or occasionally word by word, depending upon the par- 
ticular typo of transposition system involved, until the letters have been 
returned to their original plain-text order. In the case of code, the pro- 
cess consists in determining the meaning of each code group and inserting 
this moaning in the code text to reestablish the original plain text. 

b. The foregoing processes do not, as a rule, begin at the beginning 
of a message and continue letter by letter, or group by group in sequence 
up to the very end of the message. The establisnment of values of cipher 
letters in substitution methods, or of the positions to which cipher let- 
ters should be transferred to form the plain text in the case of transposi- 
tion methods, comes at very irregular intervals in the process. At first 
only one or two values scattered here and there throughout the text may ap- 
pear; these then form the "skeletons'* of words, upon which further work, 
by a continuation of the reconstruction process, is made possible; in the 



REF ID : A64644 



- 15 - 

end the complete or nearly coraplote^ toxt is established. 

In the case of cryptograms in a foreign language, the transla- 
tion of the solved messages is a final and necessary step, but is not to 
be considered as a cryptanalytic process. Hov/ever, it is commonly the 
case that the translation process mil be carried on simultaneously v/ith 
the cryptanalytic, and v/ill aid tho latter, especially when there are 
lacunae v;hich may be filled in from the context. (See also Par. 5 c in 
this connection.) 



^ Sometimes in the caso of code, tho meaning of a fow code groups may be 
lacking, because there is insufficient text to establish their meaning. 



REF ID : A64644 



- 16 - 
SiiCTIOW III. 

f.ie;uj]i:cy dist-iibutious 



Paragraph 



The simple or monoiiteral-frequency distribution 9 

Important features of the normal monoliteral frequency, bar- 

distribution . - 10 

Constancy of the standard or normal nonoliteral-frequency 

distribution 11 



9. The simple or luonoliteral-frequency distribution. - a. It has 
long been kno’vn to cryptographers and typographers that the letters com- 
posing the v/ords of any intelligible v/ritten text composed in any language 
which is alphabetic in construction are employed 'with greatly varying fre- 
quencies. For example, if on cross-section paper a simple graph, shown in 
Fig. 1, called a monoliteral freuuency, bar-distribution , is made of the 
letters comprising the words of the preceding sentence, the variation in 
frequency is strikingly demonstrated. It is seen that whereas certain 
letters, such as a, IJ, I, ii, 0^ H, S, and T, are employed very frequently, 
other letters, such as C, T-, P, and are employed not nearly so frequently, 

while still other letters, such as F, J, 'J, V, and Z are employed either 
seldom or not at all. 




A3CD3FGHIJKLLH0r'iR&TUV/XfZ 
14 3 8 4 22 2 9 10 15 0 1 9 3 17 14 8 1 13 10 20 3 1 5 1 7 0 

( Total. 200 letters) 

Fig. 1 

b. If a similar graph is now made of the letters comprising the v/ords 
of the second sentence in the preceding pe.ragraph, the graph shov/n in Fig. 2 
is obtained. Both sentences have exactly the same number caf letters (200), 




A 3 0 J Z F G H I J K L ii IJ 0 P Q R S T U V X Y Z 
12 2 8 7 25 7 5 5 19 0 1 8 6 16 14 7 2 16 14 15 3 1 2 1 8 0 

Fig. 2 



REF ID : A64644 



- 17 - 

£ Althou:5h each of these two graphs exhibits great variation in the 
relative frequencies with which different ‘letters are employed in the sen- 
tences to which they apply, no narked differences are exhibited between 
the frequencies of the same letter in the two graphs. Compare, for ex- 
ample, the frequencies of B, C, ... in Fig. 1 v;ith those of A, B, C, 

111 in Fig. 2. Aside from one or two exceptions, as in the case of the 
letter F or the letter W, these two graphs agree rather strikingly. 

d. This agreement, or s imilarit v , would be practically complete if 
the two texts were much longer, for example, five times as long. In fact, 
when two texts of similar character, each containing more than 1000 let- 
ters, are compared, it would be found that the respective frequencies of 
the 26 letters composing the two graphs show only very slight differences. 
This means, in other words, that in normal text each letter of the alpha- 
bet occurs with a rather constant or characteristic frequency v/hich it 
tends to approximate, depending upon the length of the text analyzed. 

the longer the text (within certain limits), the closer will be the ap- 
proximation.^ 

e. An experiment along these lines will be convincing. A series of 
260 official telegrams^ passing through the '<ar Department i.essage Center 
was examined statistically. The messages were divided into five sets, 
each totaling approximately 10,000 letters, and the five distributions 
shovm in Table 1 were obtained. 

f. If the five distributions in Table 1 are summed, the results are 
as shown in Table 2. 

g. The frequencies noted in subparagraph f, v/hen reduced to the basis 
of 1,000 letters and then used as a basis for constructing a simple chart 
that v/ill exhibit the variations in frequency in a striking manner, yield 
the following graph which is hereafter designated as the normal , or stand - 
ard monoliteral frequency ., bar-distribution for Bngl'ish telegraphic plain 
text ; 



^ See footnote 1 to page 23. 

2 These comprised messages from several departments in addition to the 
^Var Department, and v/ere all of an administrative character. 




REF ID : A64644 

- IS - 




ABGDEFGHIJKLiANOPQRSTUVWXrZ 
74 10 31 42130 28 16 34 74 2 3 36 25 79 75 27 3 76 61 92 26 15 16 5 19 1 

Fig. 3 



10. Irapo 'tant features of the nor.ial, monoliteral-froquency , bar- 
distribution. - a. Vi/hen the graph shown in Fig. 3 is studied in detail, 
the following features are apparent • 

(1) It is quite irregular in appearance. This 
is because the letters are used with greatly varying 
frequencies, as discussed in the preceding paragraph. 

This irregular appearance is often described by say- 
ing that the graph shows marked crests and troughs , 
that is, points of high frequency And low frequency. 



lllltHllUlttil 



REF ID^cA-64644 

*■ 

t/jble' 1-A 



Absolute froauenoie;! o£ latt-.rs appearing in five sets of Govorij- 
mental pls.in--text tclog'^^’.ms , o^ch pet containing 10,000 letters. 

Ax'raured alphabetically. 



Message 
No. 1 



Message 
No. 2 



Message 
No. 3 



Message 
No. 4 



Message 
No. 5 



Letter 

Absolute 

Frequency 


Letter 


Absolute 

Frequency 


Letter 


Absolute 

Frequency 


Letter 


Absolute 

Frequency 


Letter 


Absolute 

Frequency 


A - 738 


A 


- 785 


A 


- 681 


A 


- 740 


A 


- 741 


B - 104 


B 


- 103 


B 


- 98 


B 


- 35 


3 


- 99 


C - 519 


C 


- 300 


C 


- 238 


C 


- 326 


C 


- 301 


D - 387 


D 


- 413 


D 


- 423 


D 


- 451 


D 


- 448 


E -13G7 


E 


-1294 


E 


-1292 


E 


-1270 


E 


-1275 


F - 253 . 


F 


- 287 


F 


- 308 


F 


- 287 


F 


- 281 


G - 166 


G 


- 175 


G 


- 161 


G 


- 167 


G 


- 150 


H - 310 


H 


- 351 


H 


- 335 


K 


- 549 


H 


- 349 


I - 742 


I 


- 750 


I 


- 737 


I 


- 700 


I 


- ■797 


J - 18 


J 


- 17 


J 


- 10 


J 


- 21 


J 


- 16 


K - 36 


E 


- 38 


K 


- 22 


K 


- 21 


K 


- 31 


L - 365 


L 


- 393 


L 


- 533 


U 


- 386 


L 


- 344 


M - 242 


M 


- 240 


M 


- 238 


H 


- 249 


M 


- 268 


N - 786 


N 


- 794 


N 


- 815 


M 


- 800 


N 


- 780 


0-685 ■ 


0 


- 770 


0 


- 731 


0 


- 756 


0 


- 762 


P - 241 


P 


- 2'72 


P 


- 317 


P 


- 245 


P 


- 260 


Q - 40 


Q 


- 22 


C 


- 45 


Q 


- 58 


Q 


- 50 


R - 760 


R 


- 745 


R 


- 762 


R 


- 735 


R 


- 786 


S - 658 


S 


- 503 


S 


- 585 


S 


- 628 


S 


- G04 


T - 936 


T 


- 879 


T 


- 894 


T 

L 


- 958 


T 


- 928 


U - 270 


U 


- 253 


U 


- 31? 


u 


- 247 


U 


- 258 


V - 163 


V 


- i73 


V 


- 142 


V 


- 153 


V 


- 155 


W - 166 


W 


- 163 ' 


T. 


- 136 


T/ 


- 153 


V.r 


- 182 


X - 43 


X 


- 50 


X 


- 44 


X 


- 53 


X 


- 41 


Y - 191 


T 


- 155 


Y 


- 179 


Y 


- 213 


Y 


- 229 


Z - 14 


Z 


- 17 


Z 


- 2 


Z 


- 11 


Z 


- 5 



Totals 

10,000 10,000 10,000 10,000 10,000 



Table 2-A 



Absblute frequencies of letters apj^earing in the combined five sots 
of messages totalling 50,000 letters arr' nged alphabetically. 



A 


- 3683 


G - 


819 


L - 


1821 


Q - 


175 


V - 


766 


B 


- 487 


H - 


1694 


M - 


1237 


R - 


3788 


W - 


780 


C 


- 1534 


I - 


3676 


N - 


3975 


S - 


3058 


X - 


231 


D 


- 2i22 


i - 


82 ' 


b - 


3764 


T - 


4595 


Y - 


967 


■E 


- '6498' 


K - 


148 


P - 


1355 


U - 


1300 


Z - 


49 



F.- 1416 



-KB& ID:A64644 



(2) The relative positions in which the crests and 
troughs fall with the graph, that is, the spatial relations 
of the crests and troughs, are rather definitely fixed and 
are determined by circumstances which have been explained 
in a preceding text.^ 

(3) The relative heights and depths of the crests and 
troughs within the graph, that is, the linear extensions of 
the lines marking the respective frequencies, are also rather 
definitely fixed, as would be found if an equal volume of 
similar text v/ere analyzed. 

(4) The most prominent crests are marked by the vov/els 
A, I, 0, and the consonants N, b, T; the most prominent 
troughs are marked by the consonants T, 11, T, X, and Z. 



(5) The important data are summarized in tabular form 
in Table 3. 



T.1BL3 3 









% of /o of Total in 






Frequency 


Total Round 


[ Numbers 


6 Vowels. A E I 0 U Y . . . . 398 


39.8 


40 














5 


High Frequency .... 350 


35.0 


35 






(D il R S T) 






20 Consonants.^ 


10 


jiSdium Frequency. . . * 238 


23.8 


24 






(3 C F (J H L It F V ’/) 








5 


Low Frequency. .... 14 


1.4 


1 




V 


(J K Q X Z) 










Total. 1000 


100.0 


100 


(6) 


The frequencies of the letters of the alphabet 


are as 


follows . 








A - 74 


G - 16 L - 36 


. - 3 


V - 15 


B - 10 


H - 34 li - 25 


R - 76 


U - 16 


G - 31 


1-74 N - 79 


5-61 


X - 5 


0-42 


J - 2 0-75 


T - 92 


Y - 19 


E -130 


1; - 3 P - 27 


U - 26 


Z - 1 


F - 28 








(7) 


The relative order of frequency of the letters 


is as 


follows. 


*■ 






3 -130 


1-74 C - 31 


Y - 19 


A - 5 


T - 92 


S - 61 F - 28 


G - 16 


' ‘ - 3 


W - 79 


J - 42 P - 27 


/ - 16 


K - 3 


.( - 76 


L - 36 U - 26 


V - 15 


J - .2 


0-75 


H - 34 a - 25 


3-10 


Z - 1 



A - 74 

(8) The four vowels A, JI, I, 0 (combined frequency 353) and 
the four consonants Nj R, S, T (combined frequency 308) form 661 
out of every 1,(700 letters of plain text; in other words, less 
than 1/3 of the Alphabet is employed in writing 2/3 of normal plain 
text. 

Section VII of Special Text No. 165, Elementary military Cryptography. 



REF ID : A64644 

- 21 - 



4 



b. The data given in Fig. 3 and Table 3 represent the relative fre- 
quencies found in a large volume of ISnglish telegraphic text of a govern- 
mental, administrative character. These frequencies will vary somewhat 
with the nature of the text analyzed. For example, if an equal number of 
telegrams dealing solely with commercial transactions in the leather in- 
dustry were studied statistically, the frequencies would be slightly dif- 
ferent because of the repeated occurrence of words peculiar to that in- 
dustry. Again, if an equal number of telegrams dealing solely v/ith 
military messages of a tactical character were studied statistically, the 
frequencies would differ slightly from those found above for general gov- 
ernmental messages of an administrative character. 

£. If ordinary English literary text (such as may be found in any 
book, newspaper, or printed document) were analyzed, the frequencies of 
certain letters would be changed to an appreciable degree. This is be- 
cause in telegraphic text words wliich are not strictly essential for in- 
telligibility (such as the definite and indefinite articles, certain prep- 
ositions, conjunctions and pronouns) are omitted. In addition, certain 
essential words, such as "stop”, "period", "comma", and the like, which 
are usually indicated in written or printed matter by symbols not easy 
to transmit telegraphically and which must therefore be spelled out in 
telegrams, occur very frequently. Furthermore, telegraphic text often 
employs longer and more uncommon v/ords than does ordinary newspaper or 
book text. 

d. As a matter of fact, other tables compiled in the Office of the 
Chief Signal Officer gave slightly different results, depending upon the 
source of the text. For example, three tables based upon 75,000, 100,000, 
and 136,257 letters taken from various sources (telegrams, newspapers, 
magazine articles, books of fiction) gave as the relative order of fre- 
quency for the first 10 letters the following. 

For 75,000 letters s ETRWI0A5DL 
For 100,000 letters ; ETRINOASDL 
For 136,257 letters . ETRNAOISLD 

e. Frequency data applicable purely to printed military text were 
compiled by riitt^, from a study of 10,000 letters taken from orders and 
reports. The frequencies found by him are given in Tables 4 and 5. 

11. Constancy of the standard or normal, monolitoral-froquency 
distribution. - a. The relative frequencies disclosed by the statistical 
study of large volumes of text may bo considered to be tho standard or 
normal frequencies of tho lottors of v/ritton English. Counts made of 
smaller volumes of text v/ill tend to approximate these normal frequencies, 




^ Ijoc. cit 



pp. 6 - 



PEF ID:A64644 

- 22 - 



TABLE 4 



Froquo 


ncy 


Table 


for 10,000 Ijtt^rs of litijrary English, 
ns compilod by Hitt. 

Alphabetically arrangod. 


A - 778 


0 


- 174 


L - 372 


0-8 V - 112 


B - 141 


H 


- 595 


M 288 


R - 651 W - 176 


C - 296 


I 


- 667 


H - 686 


S - 622 X - 27 


D - 402 


J 


- 51 


0 - 807 


T - 855 Y - 196 


S -1277 
F - 197 


K 


- 74 


P - 223 


U - 308 Z - 17 



Arrangsd according to rolativo froquoncy . 



E -1277 


R - 651 


U - 303 


Y - 196 


K - 


74 


T - 855 


S - 622 


G - 296 


W - 176 


J - 


51 


0 - 807 


H - 595 


M - 283 


G - 174 


X - 


27 


A - 778 


0 - 402 


P - 223 


B - 141 


Z - 


17 


\l - 686 
I - 667 


L - 372 


F - 197 . 


V - 112 


Q - 


8 



Hitt also compilod data for tolegraphic text (but does not stato what 
kind of messages) and givos the following table; 

TABLE 5 

Frequency Table for 10,000 letters of telegraphic English, 

as compiled by Hitt . 



Alphabetically arranged . 



A - 813 


G - 201 


L - 


392 


Q - 38 


V 


- 136 


B - 149 


H - 386 


U - 


273 


R - 677 


il 


- 166 


C - 306 


I - 711 


N - 


718 


S - 656 


X 


- 51 


D - 417 


J - 42 


0 - 


844 


T - 634 


Y 


- 208 


S -1319 
F - 205 


K - 88 


P - 


243 


U - 321 


Z 


6 




Arranged according 


to relative 


f reouencv. 






E -1319 


S - 656 


U - 


321 


F - 205 


K 


- 88 


0 - 844 


T - 634 


C - 


306 


G - 201 


X 


- 51 


A - 813 


0 - 417 


il - 


273 


W - 166 


J 


- 42 


N - 718 


L - 392 


p - 


243 


3 - 149 


Q 


- 38 


I - 711 
R - 677 


H - 386 


y _ 


208 


V - 136 


Z 


6 



KEF ID:A64644 



- 23 - 

and, ’./ithin certain limits,^ the smaller the volume, the lov/er will be 
the decree of approximation to tho normal, until, in the case of a very 
short message, the normal proportions may not obtain at all. It is ad- 
visable that the student fix this fact firmly in mind, for the sooner he 
realizes the true nature of any data relative to the frequency of oc- 
currence of letters in text, the less often will his labors toward the 
solution of specific ciphers be thwarted and retarded by too strict an 
adherence to these generalized principles of frequency. He should con- 
stantly bear in mind that such data are merely statistical generalizations, 
that they will be found to hold strictly true only in large volumes of 
text, and that they may not even bo approximated in short messages. 

b. Nevertheless the normal frequency standard or the "normal ex- 
pectancy" for any alphabetic language is, in the last analysis, the best 
guide to, and the usual basis for, the solution of cryptograms of a cer- 
tain type. It is useful, therefore, to reduce the normal, monoliteral 
frequency, bar-distribution to a basis that more or less closely approx- 
imates the volume of text i.'rfiich the cryptanalyst most often encounters in 
individual cryptograms. As regards length of messages, counting only the 
letters in the body, and excluding address and signature, a study of the 
260 telegrams referred to in paragraph 9 shows that the arithmotical aver- 
age is 217 letters; the statistical mean, or weighted average'^, however, 
is 191 lottors. These tv/o results are, however, close enough together to 
warrant the statement that the average length of telegrams is approximately 
200 letters. The frequencies given in Par. 9 f have therefore been re- 
duced to a basis of 200 letters, and the following raonoliteral-frequency 
distribution may be taken as showing the most typical distribution to be 
expected in 200 letters of telegraphic English text; 



^ ^ ^ ^ ^ 

A 3 C D E F 






H I J 



K L M N 



^ ^ ^ ^ = 

0 P q R S T U V 



X Y Z 



It is useless to go beyond a certain limit in establishing the normal-fre- 
quency distribution for a given language. As a striking instance of this 
fact, witness the frequency study made by an indefatigable German, Kaeding, 
who in 1898 made a count of the letters in about 11,000,000 v/ords, totalling 
about 62,000,000 letters in German text. %en reduced to a percentage basis, 
and v/hen the relative order of frequency was determined, the results he ob- 
tained differed very little from the results obtained by Kasiski, a German 
cryptographer, from a count of only 1060 letters. See Kaeding, " Haeufig- 
keitsvfoerterbuch " . Steglitz, 1898; Kasiski, " Die Geheimschriften und die 
Dechiffrir-Kunst" , Berlin, 1363. 

^ The arithmetical average is obtained by adding each different length and 
dividing by the number of different -length messages; the mean is obtained by 
multiplying each different length by the number of messages of that length, 
adding all products, and dividing by the total number of messages. 



_ 2BEF ID:A64644 



c. The student should take careful note of the appearance of the dis- 
tribution^ shown in Fig. 4, for it will be of much assistance to him in the 
early stages of his study. The manner of setting down the tallies should 
be followed by him in making his own distributions, indicating every fifth 
occurrence of a letter by an oblique tally. This procedure almost auto- 
matically shows the total number of occurrences for each letter, and yet 
does not destroy the graphical appearance of the distribution, especially 
if care is taken to use approximately the same amount of space for each set 
of five tallies. Gross -section paper is very useful for this purpose. 



SECTION IV 

FUNDMSiJTAL USES OF THE MONOLITERiiL FREQUENCY DISTRIBUTION 

Paragraph 



The four facts which can be determined from a study of the 

raonoliteral-frequency distribution for a cryptogram. . . 12 

Determining the class to which a cipher belongs 13 

Determining whether a substitution cipher is monoalphabetic 

or polyalphabet ic 14 

Deteraining whether the cipher alphabet is a standard, or a 

mixed cipher alphabet 15 

Determining whether the standard cipher alphabet is direct 

or reversed 16 



12. The four facts which can be determined from a study of the mono- 
literal-frequency distribution for a cryptogram. - a. The following four 
facts (to be explained subsequently) can usually bo determined from an in- 
spection of the monoliteral frequency, bar-distribution for a given cipher 
message of average length, composed of letters! 

(1) Vtihether the cipher belongs to the substitution 
or the transposition class; 

(2) If to the former, whether it is monoalphabetic 
or polyalphabetic in character; 

^ The use of the terms "distribution" and "frequency distribution", in- 
stead of "table" and "frequency table", respectively, is considered ad- 
visable from the point of viev/ of consistency with the usual statistical 
nomenclature. i/hen data are given in tabular form, with frequencies in- 
dicated by numbers, then they may properly be said to be set out in the 
form of a table . iflien, however, the same data are distributed in a chart 
which partakes of the nature of a graph, v/ith the data indicated by hori- 
zontal or vertical linear extensions, or by a curve connecting points 
corresponding to quantities, then it is more proper to call such a graphic 
representation of the data a bar-distribution . 



I 





REF ID:A64644 



- 25 - 

( 3 ) If raonoalphabatic , \Aiether the cipher alpha- 
bet is a standard cipher alphabet or a mixed cipher 
alphabet ; 

( 4 ) If standard, whether it is a direct or re- 
versed standard cipher alphabet. 

b. For immediate purposes the first tv;o of the foregoipg determina- 
tions are quite important and will be discussed in detail in the next two 
subparagraphs^ the other two determinations will be touched upon very 
briefly, leaving thoir detailed discussion for subsequent sections of the 
text. 



13. Det'enaining the class to which a cipher belongs. - a. The de- 
teraination of the class to which a cipher belongs is usually a relatively 
easy matter because of the fundamental difference in the nature of trans- 
position and of substitution as cryptographic processes. In a transposi- 
tion cipher the original letters of the plain text have merely been re- 
arranged, without any change whatsoever in their identities, that is, in 
the conventional values they have in the normal alphabet. Hence, the 
numbers of vowels (A, E, I, 0, U> Y), high-frequency consonants (D, N, R, 
S, T), medium-frequency consonants (B, C, F, G, H, L, M, P, V, ’.V), and 
low-frequency consonants (J, K, Q, X, Z) are exactly the same in the 
cryptogram as they are in the plain-text message. Therefore, the per- 
centages of vowels, high, raediimi, and low-frequency consonants are the 
same in the transposed text as in the equivalent plain text. In a sub- 
stitution cipher, on the' other hand, the identities of the original let- 
ters of the plain text have bean changed, that is, the conventional values 
they have in the normal alphabet have been altered. Consequently, if a 
count is made of the various letters present in such a cryptogram, it 
will be found that the number of vowels, high, medium, and low-frequency 
consonants will usually be quite different in the cryptogram from what 
they are in the original plain-text message. Therefore, the percentages 
of vov/els, high, medium, and low-frequency consonants are usually quite 
different in the substitution text from what they are in the equivalent 
plain toxt. From these considerations it follows that if in a specific 
cryptogram the percentages of vowols, high, medium, and low-frequency 
consonants aro approximately the same as would be expected in normal 
plain toxt, the cryptogram probably belongs to the transposition class; 
if those percentages are quite different from those to be expected in 
nomal plain toxt tho cryptogram probably belongs to the substitution 
class . 



b. In the preceding subparagraph tho word "probably" was emphasized 
by underscoring it, for thore can be no certainty in ovory case of this 
dotorraination. Usually those percentages in a transposition cipher aro 
close to tho normal porcentagos for plain toxt; usually , in a substitu- 
tion cipher, they are far different from tho nomal percentages for plain 
toxt. But occasionally a cipher message is encountered v/hich is difficult 
to classify with a reasonable degree of certainty because tho message is 
too short for the gonoral principles of frequency to manifest thomsolyes. 
It is clear that if in actual messages there wore no variation whatever 



REF ID : A64644 

- 26 - 

from the normal vowel and consonant percentages given in Table 3, the de- 
termination of the class to which a specific cryptogram belongs would be 
an extremely simple matter. But unfortunately there is always some var- 
iation or deviation from the normal. Intuition suggests that as messages 
decrease in length there may be a greater and greater departure from the 
normal proportions of vowels, high, medium and low-frequency consonants, 
until in very short messages the normal proportions may not hold at all. 
Similarly, as messages increase in length there may be a lesser and lesser 
departure from the normal proportions, until in messages totalling a 
thousand or more letters there may be no difference at all between the 
actual and the theoretical proportions. But intuition is not enough, for 
in dealing with specific messages of the length of those commonly en- 
countered in practical v/ork the question sometimes arises as to exactly 
how much deviation from the normal proportions may be allowed for in a 
cryptogram that shows a considerable amount of deviation from the normal 
and might still belong to the transposition rather than to the substitu- 
tion class; 

c. Statistical studies have been made on this matter and some graphs 
have been constructed thereon. These are shown in Charts 1-4 in the form 
of simple curves, the use of v/hich will now be explained. Each chart con- 
tains tv/o curves marking the lower and upper limits, respectively, of the 
theoretical amount of deviation (from the normal percentages) of vowels or 
consona’nts which may be allowable in a cipher believed to belong to the 
transposition class. 

d. In Chart 1, curve marks the lovrer limit of the theoretical 
amount of deviation from the normal number of vov/&ls to be expected in a 
message of given length" curve Vg marks the upper limit of the same thing. 
Thus, for example, in a message of 100 letters in plain English there 
should be between 33 and 47 vowels (AEIOUY). Likewise, in Chart 2 curves 
dj|_ and H2 mark the lower and upper limits as regards the high-frequency 
consonants. In a message of 100 letters there should be between 28 and 42 
high-frequency consonants (DiLBST). In Chart 3, curves M]l 

lower and upper limits as regards the medium-frequency consonants. In a 
message of 100 letters there should be between 17 and 31 medium- frequency 
consonants (iCDFGHIiif'V /) . Finally, in Chart 4, curves L-j^ and Lg mark the 
lower and upper limits as regards the low-frequency consonants. In a 
message of 100 letters there should be between 0 and 8 low-frequency con- 
sonants (JKQXZ). In using the charts, therefore, one finds the point of 
intersection of the vertical coordinate corresponding to the length of the 
message, with the horizontal coordinate corresponding to (l) the number of 
vowels, (2) the number of high-frequency consonants, (3) the number of 
medium- frequency consonants, and (4) the number of low-frequency conson- 
ants actually counted in the message. If all four points of intersection 
fall within the area delimited by the respective curves^j then the number 
of vowels, high, medium, and low-frequency consonants corresponds with the 
number theoretically expected in a normal plain-text message of the same 
length; since the message under investigation is not plain text, it follows 
that the cryptogram may certainly be classified as a transposition cipher. 
On the other hand', if one or more of these points of intersection falls 
outside the area delimited by the respective curves, it follov/s that the 



REF ID:A64644 

- 27 - 



crypto ;raia is probably a substitution cipher. The distance that the point 
of intersection falls outside the area delinited by these curves is a more 
or less rou^h measure of the inprobability of the cryptogram's being a 
transposition cipher. 

e. Spmetimes a crypto^^raui is encountered which is hard to classify 
with certainty even with the foregoing aids, because it has been con- 
sciously prepared v/ith a view to making the classification difficult. 

This can be done either by selecting peculiar words (as in "trick crypto- 
grams'") or by employing a cipher alphabet in \Aiich letters of approxi- 
mately similar normal freouencies have been interchanged. For example, 

E may be replaced by 0, T by H, and so on, thus yielding a cryptogram 
giving external indications of being a transposition cipher but which is 
really a substitution cipher. If the cryptogram is not too short, a 
close study will usually disclose what has been done, as well as the 
futility of so simple a subterfuge. 

f. In the majority of cases, in practical work, the determination 
of the class to which a cipher of average length belongs can be made from 
a mere inspection of the message, sLfter the cryptanalyst has acquired a 
familiarity v'ith the normal appearance of transposition and of substitu- 
tion ciphers. In the former case, his eyes very speedily note many high- 
frequency letters, such as T, H, H, 0, and S, v/ith the absence of low- 
. frequency letters, such as J, K, Q, X, and Z; in the latter case, his 
eyes just as quickly note the presence of many lov/-frequency letters, and 
a corresponding absence of the usual high-frequency letters. 

' g. linother rather quickly completed test, in the case of the simpler 
varieties of ciphers, is to look for repetitions of groups of letters . As 
will become apparent very soon, recurrences of syllables, entire words and 
short phrases conotibuta a characteristic of all normal plain text. Since 
a transposition cipher involves a change in the sequence of the letters 
.composing a plain-text message , such recurrences are broken up so that the 
cipher text no longer will shov/ repetitions of more or less lengthy se- 
quences of letters, nut if a cipher message does show many repetitions 
and these are of several letters in length, say over four or five, the 
conclusion is at once v/arranted that the cryptogram is most probably a 
substitution and not a transposition cipher, however, for the beginner in 
cryptanalysis, it ivill be advisable to nial:e the monoliteral frequency, 
bar-distribution, -and note the frequencies of the vowels, the high, medium, 
and lov/-. frequency consonants. Then, referring to Charts 1 to 4, he should 
carefully note v’hether or not the observed frequencies for these categories 
of, letters fall v/ithin the limits of the theoretical frequencies for a 
normal plain-text message of the same length, and be guidod accordingly. 

h. It is obvious that the foregoing rule applies only to ciphers com- 
posed, wholly of letters. If a message is composed entirely of figures, or 
of arbitrary signs and symbols, or of intermixtures of letters, figures and 
other symbols, it is immediately apparent that the cryptogram is a sub- 
stitution cipher 



REF ID:A64644 

28 - 



i. Finally, it should he mentioned that there are certain kinds of 
cryptograms whose class cannot be determined by the method set forth in 
subparagraphs b, c,, d above. These exceptions v/ill be discussed in a sub- 
sequent section of this text. 

14. Determining v/hether a substitution cipher is monoalphabetic or 
polyalphabetic . - a. It will be reraembored that a monoalphabetic sub- 
stitution cipher is one in which a single cipher alphabet is employed 
throughout the whole message, that is, a given plain-text letter is in- 
variably represented throughout the message by one and the same letter in 
the cipher text. On the other hand, a polyalphabetic substitution cipher 
is one in which two or more cipher alphabets are employed v/ithin the same 
message; that is, a given plain-text letter may be represented by tv/o or 
more different letters in the cipher text, according to some rule govern- 
ing the selection of the equivalent to be used in each case. From this 
it follows that a single cipher letter may represent two or more different 
plain-text letters. 

•b. It is easy to see why and how the appearance of the monoliteral” 
frequency distribution for a substitution cipher may be used to determine 
•whether the cryptogram is monoalphabetic or polyalphabetic in character. 

The normal distribution presents marked crests and troughs by virtue of 
two circumstances. First, the elementary sounds vfhich the symbols repre- 
sent are used v/ith greatly varying frequencies, it being one of the strik- 
ing characteristics of every alphabetic language that its elementary sounds 
are used with greatly varying frequencies.® In the second place, except 
for orthographic aberrations peculiar to certain language (conspicuously, 
jJnglish and French), each such sound is represented by the same symbol. 

It follows, therefore, that since in a monoalphabetic substitution cipher » 

each different plain-text letter ( = elementary sound) is represented by 
one and only one cipher letter ( = elementary symbol), the raonoliteral-fre- 
quency distribution for such a cipher message must also exhibit the ir- 
regular crest and trough appearance of the normal distribution, but with 
only this important modification- the absolute positions of the crests 
and troughs vji ll not be the same as in the normal . That is, the letters 
accompanying the crests and the troughs in the distribution for the crypto- 
gram will be different from those accompanying the crests and the troughs 
in the normal distribution. But the marked irregularity of the distribu- 
tion, the presence of accentuated crests and troughs, is in itself an in- 
dication that each symbol or cipher letter alv/ays represents the same 
plain-text letter in that cryptogram. Hence the general rule. A marked 
crest and trough appearance in the nonoliteral^frequency distribution for 
a.. given cryptogram indicates that a single cipher alphabet is involved and 




REF ID : A64644 

- 29 - 



c. On the other hand, suppose that in a cryptogram each cipher let- 
ter represents several different plain-text letters. Some of them are of 
high frequency, others of low frequency. The net result of such a situa- 
tion, so far as the monoliteral frequency distribution for the cryptogram 
is concerned, is to prevent the appearance of any marked crests and troughs 
and to tend to reduce the elements of the distribution to a more or less 
common level. This imparts a "flattened out" appearance to the distribu- 
tion. For example, in a certain cryptogram of polyalphabet ic construc- 

t X on , , ^^p ^ and Jp5 ^c * "^p? and Bpii Xg — Op, tip, and Fp. The 

frequencies of Kg, Rg and X^, will be approximately equal because the sum- 
mations of the frequencies of the several plain-text letters each of these 
cipher letters represents at different times will be about equal. If this 
same phenomenon were true of all the letters of the cryptogram, it is clear 
that the frequencies of the 26 letters, v/hen shown by means of the ordin- 
ary raonoliteral frequency distribution, would shov/ no striking differences 
and the distribution vrould have the flat appearance of a typical polyalpha- 
betic substitution cipher. Hence, the general rule The absence of 
m arked crests and troughs in the raonoliteral-frequency distribution in - 
dicates that two or more cipher alphabets are involved. The flattened-out 
appearance of the distribution constitutes one of the tests for a poly- 
alphabetic substitution cipher. 

d. The foregoing test based upon the appearance of the frequency 
distribution constitutes only one of several means of determining whether 
a substitution cipher is monoalphabetic or polyalphabetic in composition. 

It can be employed in cases yielding frequency distributions from which 
definite conclusions can be drawn with more or less certainty by mere 
ocular examination. In those cases in which the frequency distributions 
contain insufficient data to permit drawing definite conclusions by such 
examination, certain statistical tests can be applied. These will be dis- 
cussed in a subsequent text. 

e. At this point, however, one additional test will be given because 
of its simplicity of application. It may be employed in testing messages 
up to 200 letters in length, it being assumed that in messages of greater 
length ocular examination of the frequency distribution offers little or 

‘no difficulty. This test concerns the number of blanks in the frequency 
distribution, that is, the number of letters of the alphabet which are en- 
tirely absent from the message. It has been found from statistical studies 
that rather definite "laws" govenx the theoretically expected number of 
blanks in normal plain- text messages and in frequency distributions for 
cryptograms of different natures and of various sizes. The results of 
certain of these studies have been embodied in Chart 5. 

f. This chart contains two curves. The one labeled P applies to the 
average number of blanks theoretically expected in frequency distributions 
based upon normal plain-text messages of the indicated lengths. The other 
curve, labeled R, applies to the average number of blanks theoretically ex- 
pected in frequency distributions based upon perfectly r andom assortments 
of letters, that is, assortments such as ’.yould be found by random selec- 
tion of letters out of a hat containing thousands of letters, all of the 



REF ID:A64644 

- 30 - 

25 letters of the alphabet being present in equal proportions, each let- 
ter being replaced after a record of its selection has been made. Such 
random assortaents correspond to polyal]3habetic cipher messages in which 
the number of cipher alphabets is so large that if uonoliteral- frequency- 
distributions are made of the letters, the distributions are practically 
identical with thoso which are obtained by random selections of letters 
out of a hat. 

g. In using this chart, one finds the point of intersection of the 
vertical coordinate corresponding to the length of the message, with the 
horizontal coordinate corresponding to the observed number of blanks in 
the monoliteral- frequency distribution for the message. If this point of 
intersection falls closer to curve P than it does to curve R, the number 
of blanks in the message approximates or corresponds more closely to the 
number theoretically expected in a plain-text message than it does to a 
random cipher-text message of the same length? therefore, this is evidence 
that the cryptogram is monoalphabetic. Conversely, if this point of inter- 
section falls closer to curve R than to curve P, the number of blanks in 
the message approximates or corresponds more closely to the number theo- 
retically expected in a random text than it does to a plain-text message 

of the same length? therefore, this is evidence that the cryptogram is 
polyalphabetic . 

h. Practical examples of the use of this chart \’ill be given in some 
of the illustrative messages to follow. 

15. Determining whether the cipher alphabet is a standard, or a mixed 
cipher alphabet. - a. Assuming that the monoliteral- frequency distribu- 
tion for a given cryptogram has been made, and that it shows clearlj^ that 
the cryptogram is a substitution cipher and is monoalphabetic in character, 
a consideration of the nature of standard cipher alphabets^ almost makes 

it obvious how an inspection of the distribu-tion will disclose whether the 
cipher alphabet involved is a standard cipher alphabet or a mixed cipher 
alphabet. If the crests and troughs of the monoliteral-frequency distribu- 
tion occupy positions which correspond to the relative positions they oc- 
cupy in the normal- frequency distribution, then the cipher alphabet is a 
standard cipher alphabet. If this is not the case, then it is highly prob- 
able that the cryptogram has been prepared by the use of a mixed cipher 
alphabet . 

b. A mechanical test may be applied in doubtful cases arising from 
lack of material available for study. Just vhat this test involves, and 
an illustration of its application -will be jiven in the next section, using 
specific examples. 

16. Determining -whether the standard cipher alphabet is direct or 
reversed. - Assuming that the monoliteral- frequency distribution for a 
given cryptogram shows clearly that a standard cipher alphabet is involved, 
the determination as to whether the alphabet is direct or reversed, can also 



See i^r. 41, Special Text No. 165, ISlementary military Cryptography. 



REF ID:A64644 

- 31 - 



be made by inspection} since the difference between the two is merely a 
matter of the dire ct ion in which the sequence of crests and troughs pro- 
gressesi to the riTht, as in nornal reading or v/riting, or the left. 

In a direct cipher alphabet the direction in T,»hich the crests and troughs 
of the monoliteral-frequency distribution should be read is the normal 
direction, from left to right] in a reversed cipher alphabet this direc- 
tion is reversed, from right to left. 



SECTION V. 

,.ONOLIT]RaL oUBoTirUTIOiJ WITH STA.TJ.-iRD CIPII]R .iLPHaBJTS 



Paragraph 

Principles of solution by construction and analysis of the 



monolit oral-frequency distx-ibution 17 

Theoretical example of solution 13 

Practical example of solution by the frequency method ..... 19 



Solution by completing the plain-component sequence 20 

Special remarks on the method of solution by completing the plain- 



component sequence 21 

Value of mechanical solution as a short cut 22 



17. Principles of solution by construction and analysis of the mono- 
literal-frequency distribution. - a. Standard cipher alphabets are of two 
sorts, direct and reversed. The analysis of nonoalphabetic cryptograms 
prepared by their use follows almost directly from a consideration of the 
nature of such alphabets. Since the cipher component of a standard cipher 
alphabet consists either of the normal sequence merely displaced 1, 2, 3 
... intervals from the normal point of coincidence, or of the normal se- 
quence proceeding in a reversed-normal direction, it is obvious that the 
raonoliteral-frequency distribution for a cryptogram prepared by means of 
such a cipher alphabet employed raonoalphabetically will show crests and 
troughs whose relative positions and frequencies will be exactly the same 
as in the raonoliteral-frequency distribution for the plain text of that 
cryptogram. The only thing that has happened is that the whole set of 
crests and troughs of the monoliteral-frequency distribution has been dis- 
placed to the right or left of the position it occupies in the raonoliteral- 
frequency distribution for the plain text; or else the successive elements 
of the whole set progress in the opposite direction. Hence, it follows 
that the correct determination of the plain-text value of the letter mark- 
ing any crest or trough of the inonoliteral-frequency distribution will re- 
sult at one stroke in the correct determination of the plain-text values 
of all the remaining 25 letters respectively marking the other crests and 
troughs in that distribution. Thus, having determined the value of a 
single element of the cipher component of the cipher alphabet, the values 



REF ID : A64644 

32 - 



of all the retnainin^ letters of the cipher component are automatically- 
solved at one strolce. In more simple language, the correct determination 
of the value of a single letter of the cipher text automatically gives the 
values of the other 25 letters of the cipher text. The problem thus re- 
solves itself into a matter of selecting that point of attack y/hich will 
most quickly or most easily lead to the determination of the value of one 
cipher letter. The single word identification v/ill hereafter be used for 
the phrase "determination of the value of a cipher letter"; to identify a 
cipher letter is to find its plain-text value. 

b. It is obvious that the easiest point of attack is to assume that 

the letter marking the crest of greatest frequency in the monoliteral- 
frequency distribution for the cryptogram represents l-’roceeding from 

this initial point, the identifications of the remaining cipher letters 
marking the other crests and troughs are tentatively made on the basis 
that the letters of the cipher component proceed in accordance vri.th the 
norinal alpiabetic sequence, either direct or reversed. If the actual 
frequency of each letter marking a crest or a trough approximates to a 
fairly close degree the normal theoretical frequency of the assumed plain- 
text equivalent, then the initial identification * 3p may be assumed to 
be correct and therefore the derived identifications of the other cipher 
letters may be assumed to be correct. If the original starting point for 
assignment of plain-text values is not correct, or if the direction of 
"reading" the successive crests and troughs of the monoliteral-frequency 
distribution is not correct, then the frequencies of the other 25 cipher 
letters ’dll not correspond to or even approximate the normal theoretical 
frequencies of their hypothetical plain-text equivalents on the basis of 
the initial identification. A new initial point, that is, a different 
cipher equivalent must then be selected to represent Ep; or else the direc- 
tion of "reading" the crests and troughs must be reversed. This procedure, 
that is, the attempt bo make the actual frequency relations exhibited by 
monoliteral-frequency distribution for a given cryptogram conform to the 
theoretical frequency relations of the normal-frequency distribution in an 
effort to solve the cryptogram, is referred to technically as "fitting the 
actual monoliteral-frequency bar distribution for a crypbogram to the theo- 
retical monoid teral-frequency bar distribution for normal plain text", or, 
more briefly, as " fitting the frequency distribution for the cryptogram to 
the normal-frequency distribution ," or, still more briefly, " fitting the 
distribution to the normal ." In statistical work the expression commonly 
employed in connection ’.dth this process of fitting an actual distribution 
to a theoretical one is "testing the goodness of fit". The closeness of 
the degree of goodness of fit may be stated in various v/ays, mathematical 
in character. 

c. In fitting the distribution to the normal, it is necessary to re- 
gard the cipher component (that is, the letters A ... Z marking the succes- 
sive crests and troughs of the monoliteral-frequency distribution) as par- 
taking of the nature of a wheel or sequence closing in uuon itself, so that 
no matter with v/hat crest or trough one starts, the spatial and frequency 
relations of the crests and troughs are constant. This manner of regard- 
ing the cipher component as being cyclic in nature is valid because it is 



REF ID:A64644 

- 33 - 



obvious that the relative positions and f requencies of the crests and 
troughs of any monoliteral-freguencv distribution must remain the same 
regardless of what letter is employed as the initial point of the dis- 
tribution . Fig. 5 gives a clear picture of v/hat is meant in this con- 
nection, as applied to the normal- frequency distribution. 




Fig. 5 

d- In the third sentence of subparagraph b, the phrase “assumed to 
be correct” was advisedly employed in describing the results of the at- 
tempt to fit the distribution to the normal, because the final test of 
the goodness of fit in this connection (that is, of the correctness of 
the assignment 'of values to the crests and troughs of the inonoliteral- 
frequency distribution) is whether the consisten t substitution of the 
plain-text values of the cipher characters in the cryptogram will yield 
intelligible plain text. If this is not the case, then no matter how 
close the approximation between actual and theoretical frequencies is, no 
matter how well the raonoliteral-frequency distribution fits the normal, 
bhe only possible inferences are that (l) either the closeness of the fit 
is a pure coincidence in this case, and that another equally good fit may 
be obtained from the same data, or else (2) the cryptogram involves some- 
thing ’.lore than simple raonoalphabetic substitution by means of a single 
standard cipher alphabet. For example, suppose a transposition has been 
applied in addition to the substitution. Then, although an excellent 
correspondence between the raonoliteral-frequency distribution and the 
normal-frequency distribution has been obtained, the substitution of the 
cipher letters by their assumed equivalents will still not yield plain 
text, however, aside from such cases of double encipher. lent , instances 
in which the raonoliteral-frequency distribution may be easily fitted to 
the normal— frequency distribution and in which at the same time an attempted 





REF ID : A64644 

- 34 - 

siinple substitution fails to yield intellijible text are rare. It may be 
said that, in practical operations ’vVienever the aonoliteral-frequency 
distribution can be naJe to fit the iiomal- frequency distribution, sub- 
stitution of values 'vill result in solution; and, as a corollary, v/henever 
the raonoliteral-frequency distribution cannot be nade to fit the normal- 
frequency distribution, the cryptogram does not represent a case of simple, 
raonoalphabetic substitution by means of a standa 'd alphabet. 

13, Theoretical example of solution. - a. The foregoing principles 
will become clearer by noting the crypt ographing and solution of a theo- 
retical example. The following aessa-.e is to be crypt ographed. 

- HOSTILE /0:iC::’xi;STi; ATED ..T one .-bilG-L'.ElIT IUFaETRY 

AND T .'0 ILiiTOOKS CAVaLTf ■ :0VIHG bOUTH OP -jUIn'HL ONT 
PIKE STOP iIEAD OF C0LU...-J .ISA HIM RO.-ii) JUNCTION SEVEN 
THREE SEVEN COi.iiA EAST OF GRiSSNACRE SCHOOL FIAli) UPON 
JY OUR i^AflOLS STOP HaVE JEoTHOYEO SRUGE OVER INJI.iN 
CREEK 

b. First, solely for purposes of demonstrating certain principles, 
the nonoliteral-frequency distribution for this message is presented in 
Fig. 6. 













BE 






^ ^ 


BE 










£ 


BE 




E BE mE 


_ B 




AS'COEFGHIJK 


L 1. N 0 P 


'i R 


S T U V ■./ 



Fig. 6 



c. Now let the foregoing nessage be crypbographed monoalphabetically 
by the follov/ing cipher alphabet, yielding the cryptogram and the mono- 
literal-frequency distribution shovm below. 

Plain. A 3 C D E F G H I J L . N 0 r J R o T U V / X Y Z 
Cipher. GrilJKL*. NOP iRSTUV /XYZA3CDEF 



REF ID:A64644 



- 35 - 



Plain • 


H 


0 


s 


T 


I 


L 


.■3 


F 


0 


R 


G 1 


13 -S 


T 


I 




A 


T 


3 


D 


A 


T 


0 


N 


3 


R 


3 G I 


Cipher; 


W 


u 


Y 


Z 


0 


rt 


u 


L 


u 


-r 

A 


I i: 


L f 


Z 


0 


i5 


G 


Z 


K 


J 


G 


Z 


u 


T 


K 


X 


K 1.1 0 


Plain • 


1 




H 


i 


I 


N 


F 


ii 


M 


T 


R Y 


A 11 


D 


T 


1 


0 


P 


L 


'A 


T 


0 


0 


N 


0 


C 


A V A 


Cipher" 


s 




T 


z 


0 


T 


L 


rt 

sT 


T 


Z 


X 3 


j- T 


J 


Z 


c 


U 


V 


1 
. W 


G 


Z 


U 


u 


T 


Y 


I 


G 3 G 


rlain i 


L 


R 


Y 




0 


y 


I 


N 


G 


S 


0 U 


r li 


0 


11 


{ 


u 


I 


N 


il 


I 




0 


N 


' T 


P 


IKS 


Ciphers 


R 


X 


T 


b 


U 


3 


0 


rp 

J. 


1 _ 


Y 


U A 


Z 1 


U 


T 


1 


A 


0 


T 


T 


0 


s 


u 


T 


Z 


V 


0 'J K 


rlain 


S 


T 


0 


P 


H 


3 


A 


D 


0 


F 


C 0 


L U 


aI 


11 


il 


3 


A 


. 1 . 


I 


N 


G 


R 


0 


A 


D 


J U 11 


Cipher. 


Y 


Z 


u 


V 


R 


Ti’" 

Ik. 


G 


J 


u 


L 


I U 


R A 


s 


T 


T 


K 


G 


X 


0 


T 


i. 


X 


U 


G 


J 


PAT 


Plain • 


C 


T 


I 


0 


't 


S 


n 


y 


1 


II 


T H 


R 33 


1 

-J 


S 


il 


y 


1 

il 


il 


C 


0 


1 . 


1 1 


A 


■3 


A 


S T 0 


Cipher. 


I 


Z 


0 


u 


T 


Y 


r 


3 


ik 


T 


Z li 


X ! •: 


Iv 


Y 


il 


k 

Jj 


1 ■ 


T 


I 


U 


3 


s 


G 


i: 


G 


Y Z U 


Plain . 


F 


G 


R 


1 


Ji 


w 


A 


c 


1 

i-k 


1 


S C 


H 0 


0 


L 


F 


I 


• 


3 


D 


U 


r 


0 


i; 


3 


ir 


OUR 


Cipher- 


L 


j 


X 




K 


T 


a 


I 


X 


K 


Y I 


:■ u 


u 


H 


L 


0 


ir 

jL 


T/* 

iV 


J 


A 


y 


u 


T 


xl 


1 : 


U A X 


Plain - 


t 


Ji 


T 




0 


L 


5 


3 


T 


0 


r ’1 


A V 




jJ 




3 


T 


■V 

k 


0 


Y 


“1 

..J 


J 


J 


R 


I 


D G S 


Cipher. 


V 


■J 


Z 


A U 


R 


/ 


Y 


Z 


U 


V 11 


G 3 


- 


J 


iC 


Y 


Z 


X 


U 


3 


ik 


J 


xR 


X 


0 


J i,i K 


rlain • 


0 


y 




1. 


I 


N 


J 


I 


.1 


R 


C 1 


^ 1 

^ .J 


K. 




























.Cipher. 


u 


3 




J\. 


0 


1 


J 


0 


j 


T 


I X 


K K 












; 


















Cryptogram. 
























































u 


Y 


z 


0 


R 


u 


L 


u 


X 


I - 


Y 


Z 


0 


3 


G 


Z 


K 


J 


G 


z 


u 


T 


K 


X 


K . 0 




s 


K 


T 


z 


0 


T 


L 


G 


T 


Z 


X .5 


G T 


J 


Z 


C 


U 


V 


R 


G 


X 


u 


u 


T 


Y 


I 


G 3 G 




R 


V 

J\ 


i 


s 


u 


3 


0 


T 


• 1 . 


Y 


U A 


Z 11 


u 


T 


/ 


A 


0 T 


T 


0 


3 


u 


T 


Z 


y 


0 ; K 




Y 


z 


U 


V 


i ' 


K 


n 

\X 


J 


U 


L 


I U 


R A 


s 


T 


T 


K 


r, 

or 


X 


0 


T 




X 


U 


"1 

CT 


J 


x' A T 




I 


z 


0 


u 


T 


Y 


Is 


J 


K 


T 


z :i 


X K 


K 


Y 


1 . 


B 


l'» 


T 


r 


U 


3 


6 


G 


X 


G 


Y Z U 




L 


X . 


X 


K 


lb 


T 


nZ 


fr 

a. 


X 


K 


Y I 


N 0 


U 


R 


L 


0 


X 


IC 


J 


A 


y 


U 


T 


H 


.3 


U A X 




V 


'i 

JC 


Z 


X 


u 


-R 


Y 


Y 


Z 


U 


V :1 


G 3 


K 


J 


K 


Y 


z 


X 


u 


jj 


K 


J 


H 


X 


0 


J il K 




U 


B 


K 


X 


0 


T 


J 


0 


G 


T 


IX 


K i: 


T 

H 




























' 




























































































S 


r 






























. 


T*- 






dn 














z 


r 



























- . 
























^ . 










S -fc. 


— 




r 








3 










— 


— 


: 3 










— 






ABC 




s 


F 


G 


H 


<1 




J 


K 


L 1 


11 


0 


P 


r 

( 


1 


R 


s 


T 


u 


V 


; 


X 


Y 


• z 



Fig. 7 



d. Let the atiident now compare Figs. 6 and 7, which have been super- 
imposed in Fig. 8 for convenience in examination. Crests and troughs are 
present in both distributions; moreover, their relative positions and fre- 
quencies have not been changed in the slightest particular. Only the absolute 



REF ID:A64644 



-36- 



positi'^n *f the sequence as a whole has been displaced six intervals t» 
the right in Fig. 7, as compared with the absolute position »f th? sequence 
in Fig. 6. 




ABGDEFGHIJKLMNOPQRSTUVWXY.Z 




ABCDEFGH 



IJKLMNOPQRSTUVWXYZ 
Fig. a 



e* If the two distributions are compared in detail the student will 
clearly understand how easy the solution of the cryptogram would be to one 
who knew nothing about how it was prepared. For example » the frequency »f 
the highest crest, representing E in Fig. 6 is 28; at an interval of three 
letters before E there is another crest representing A with frequency 16. 
Betweeaa A and E there is a trough, representing the lowSfrequency letters 
B, C, D. On the other side of E, at an interval of three letters, (Jomes 
another crest, representing I with frequency 14. Between E.and I there is 
another trough, representing the low-frequency letters F, G, H. Compare 
these crests and. troughs with their homologous crests and troughs in Fig. 

7. In the latter, the letter K marks the highest crest in the raonoliteral- 
frequency distribution with a frequency of 28; three letters before K there 
is another crebt, frequency 16, and three letters on the other side of K 
there is another crest, frequency 14. Troughs corresponding to B, C,. D and 
F, G, H are seen at^H, I, J and L, M, N in Fig. 7. In fact, the two dis- 
tributions may be made to coincide exactly, by shifting the monoliteral- 
frequency distribution for the cryptogram six intervals' to the left with 
respect to the monoliteral-frequency distribution for the equivalent plain- 
text message, as shown herewith. 



REF ID:A64644 



- 37 - 




ABGDJFGHIJKLMNOPQRSTUVWXYZ 




GHIJKLMNOPQRSTUVWXYZABCDEF 

Fig. 9 

f. Let us suppose new that nothing is known about the cryptographing 
process, and that only the cryptogram and its monoliteral- frequency distribu- 
tion is at hand. It is clear that simply bearing in mind the spatial relations 
of the crests and troughs in a normal-frequency distribution would enable the 
cryptanalyst to fit the moncliteral-froquency distribution to the normal- 
frequency distribution in this case* Ho v/ould naturally first assume that 

Gc = from which it would follow that if a direct standard alphabet is 
involved, - B , s Op, and so on, yielding the following (tentative) 
deciphering alphabet t 

Cipher: ABCDEFGHIJKLMNOPQRSTUVWXYZ 

Plain : UVWXYZABG BEFGHIJKLMNCPQRST 

g. Now c canes the final test: If these assumed values are substituted 

in the cipher text, the plain text immediately appears. Thus: 

NUYZO RKLUX IKKYZ OSGZK JGZUT etc. 

HOSTI LEFOR OEEST IMATE BATON etc. 

h. It should bo clear, therefore, that the selection of G^ to repre- 
sent A in the cryptographing process has absolutely no effect upon the 
relative spatial and frequency relations of the crests and troughs of the 
monoliteral-frequency distribution for the cryptogram. If had been selected 
to represent A , these relations would still remain the same, the whole series 
of crests and troughs being merely displaced further to the right of the 

positions they occupy when G_ - A . 

c p 



REF ID:A64644 

- 38 - 

19. i^ractical example of solution by the frscjuency method. - a. The 
cas e of direct stan dard .aljgha.bejt ciph ers. 

(1) The folio crypto-jram is to be solved by ap- 
plyin'T the Pore'^oing principles 

I 3 M -1 o P B I IT 0 M B B G A J G Z 0 F U U 'j B A J C 

Z 17 I .L N . T T K L 3 B F U I Z K P T y 0 7 J I V 3 

(2) From t'le presencb of repatitioiiB and so many 

lo\/-f requencv letters such as Bj and Z it is at once 
suspected that this is a substitution cipher, -jut to 
illust-abe ^he stsps that must be tahen in difficult 
cases in ordor to be certain in this .-espect, a nono- 
literal-frequency distribution is constructed, and then 
reference is 'riaae to cha±’ts 1 to 4 to note here the 
actual nu.-ibsrs of vowels j hi;h, aedium, and lov-fre- 
ouency letters fall insiue or outside the a eas de- 
limited by the respective curves. 



= ~ — ~ ^ — _ — 




2 ? = i 






.V 3 C D T F G H I J i: L 


h 


U 0 F 


I R S T U V y X Y 


Z 


Tig. 


10 


a. 


rosition with respect 


to 


■ 




Frequency 


areas dali it 3d by curves 


'0 ;3ls .1 i I 0 U : 




17 


outsiae, Cha-t 1 




high-frequency Gonnoiants (o N R 0 
Tediu 1 -freouenc j Consonants 


T) 


4 


outsisie, Cha t 2 




'vB' C F J I 1 . Id r 7 U) 




25 


outsiae, Chart 3 




Low-frequency Consonants (J Q X Z) 


• 14 


outside y Chart 4 




Total 




go" 






(3) xill four points 


falling quite 


outside the 





areas delimited by the curves applicable to these four 
classes of letters^ the crvptogra . is clearly a sub- 
stitution ci-'ie.'. 

( 4 ; The appearance of the frequency distribution, 
with ..larred crests and troughs, indicates that the 
cr/ptogrnm is probably lonoalj.habetic . -Leference is 
ho’./ .lade to Chart 5. The message has 60 ‘letters and 
6 blanLs. Tie point of intersection on the c.iart is 
closer to curve F than it is to curve C, therefore, 
this is additiTnal evidence that the message is prob- 
ably Lionoal^ahabetic. 

(5'j The 'next step is to determine whether a stand- 
ard or a mixed cipher alphabet is involved. This is - 
done by studving the sequence of crests and trou;hs in 
the monoliteral-frequenc y dist ibutron, and t dng to 
fit the distribution to the nor’aal. 



REF ID : A64644 

~ 39 - 



(fi) The assumpbion to be made is that a 

direct standard is involved. The hi-rhast crest in 
the aistribution is marked by Let it be assumed 

that Bq = ]ilp. Then G^, Bj., , ... = Fp, Gp, Hp, thus. 

•Sc IS” 4e it ^ tir— 

Cipher .. B C J F G .1 I J K L M W U P Q Id S T U V V/ X Y Z 
Plain . D ] F G H I J K L II N 0 P R S T U V \7 X Y Z A B C 

Fig. 10 JD. 

at first glance the approximation to the expected fre- 
quencies seems fair, especially in the region F G PI I 
J K and R S 1^. But there are too many occurrences 
of fjp, r^p, Xp and Cp and too fev/ occurrences of Ap, Ip, 

lip. Op. iioreover, if a substitution is attempted on 
this basis, the follo’.7ing is obtained for the first two 
cipher groups 

Cipher . I B Li Q o P B I U 0 

"rlain text" .L3PTR S3LXR 

This is certainly not plain text and it seems clear 
that Bp is not Ep. A different assuiption will have 
to be made. 

(7) Suppose Qg = 3p. Going through the same 
steps as before, again no satisfactory results are 
obtained. Further trials^ are made along the same 
lines, until the assu-iption LI^. = Ep is tested. 



^ 4k .4^ — A ^ ^ ^ ^ ^ S — S 

Cipher- .1 B C J 3 F G ii I J K L LI'iI 0 P Q R S T U V / X Y Z 

1-lain . S T U V 17 X Y Z 3 C J 3 F G H I J K L L N 0 P '2 R 

J'ig. 10 c. 

(a) The fit in this case is quite good; possibly 

there are too many occurrences of G and ii and t\m 

few of 3^, 0 and S„. But the final test remains, 

P P P 

trial of the substitution alphabet on the cryptogram 
itself. This is inraediately done and the results are 
as follows < 



It is unnecessary, of course, to write out the alphabets as shown in 
Figs. 10 b and c. v/hen testing assu’ptions. This is usually all done 
mentally. 



REF ID:A64644 



- 40 - 



Crypto ;ram. 


I 




M 


Q 


0 


P 


3 


I 


U 


0 


3 


B 


G 


A 


J 


c 


z 


0 


F 


ii 


U 


U 


1 3 


i-lain text . 


A 


T 


E 


I 


G 


H 


T 


A 


il 


G 


E f 


T 


Y 


S 


B 


u 


R 


n 

cr 


X 


E 


IJ 


LI 


I T 


'Cryptogram. 


A 


J 


c 


z 


0 


Z 


y 


I 


L 


11 


'i T 


T 


1- 


L 


jZj 




B 


p 


u 


I 


Z 


K 


r Q 


Plain text. 


s 


1 


U 


R 


G 


R 


0 


A 


D 


F 


I L 


L 


E 


D 


J 


i 


T 


H 


li 


A 


R 


C 


H I 


Crypt-bgrara: 


y 


0 


. i 


V 


iJ '■ 


,I 


■y 


3 


■z 


G 


•7- -> 












\ 














Plain text s 


N 


hr 


1 


N 


f" 


'a 


N 


T 


R, 


y ' 



























AT 3I?tHT Aji G3TT/SiiU'lG-I]liMITS3UAG ROaD FILL3D VifflTH 
MARCHIiJG IrfFAlWRY. 



(9) It is always advisable to note the specific 
key. In this case the correspondence between any plain- 
t.ext letter and its cipher equivalent will indicate the 
keyj it is usual, however, to indicate the key by not- 
ing the cipher equivalent of in this case Ap Ig. 

The case of reversed standard alphabet cip hers. - 

(1) Lat the following crypto ^'ram and its mono- 
literal-frequency distribution be studied- 

IF3AC 3FIWC iilPPKQ HORCL D'V/WAP -330 3 0 

RUIFJ AXXEF MAPBW IRGBA VCAVD IVPRK 

(2) The preliminary steps illustrated above, under 
subpar, a (l) to (4) inclusive, in connection v/ith the 
test for class and monoalphabeticity , will here be 
omitted, since they are exactly the same in nature. 

The result is that the cryptogram is obviously a sub- 
stitution cipher and is monoalphabetic . 

C3‘) assuming tha't it is 'hot known whether a direct 
or a reversed standard alphabet is involved, attempts 
are at once made to fit the raonoliteral-f requency dis- 
tribution to the direct sequence. If the student will 
try them he will soon find out that these are unsuc- 
cessful. .iill this takes but a fev/ minutes. 

( 4 ) The next logical assumption is now made, viz., 
that the cipher alphabet is a reversed standard alpha- 
bet. ftien on this basis 3^, is assumed to be Ep, the 
distribution can readily be fitted to the normal, 
practically every crest and trough in the actual dis- 
tribution corresponding to a crest or trough in the ex- 
pected distribution, 

— s 

Cipher- 'ABCDEFGHIJKL'’lI0P'3RSTUV*XyZ 
Plain . I H G F E D C B A Z Y X ; V U T S R Q P 0 II L II J 

Fig. 10 d 



REF ^IJ>:A64644 



(5) '.ifien the substitution is made in the crypto- 
gram, the following is obtained. 

Cryptogram. IPI3AG 3PI\/C SPPKQ ... 

Plain texti ATJIG HTAIIG 3TTYS ... 

(6) The plain-text message is identical with that 
under paragraph a. The specific key in this case is 
also Ap = !(.. If the student will compare the frequency 
distributions in the two cases, he vjill note that the 
relative positions and extensions of the crests and 
troughs are identical; they merely progress in opposite 
directions. 

20. Solution by completing the plain-component sequence. - 
a* The ca se of direct standard a lphab e t cipher s. - 

(1) The foregoing method of analysis, involving 
as it does the construction of a monoliteral-frequency 
distribution, \ as termed a solution by t he frequenc y 
method because it involves the construction of a fre- 
quency distribution and its studv. There is, hovrever, 
another method which is much more rapid, almost wholly 
nechanical, and which, moreover, does not necessitate 
the construction or study of any freouency dist.ibu- 
tion whatever. An understanding of the method follows 
from a consideration of the method of enciphennent of 

a message by the use of a single, direct standard cipher 
alphabet. 

(2) ilote the follo\/ing encipherment. 

1 -ess age". R'J:P3L INVaDIHG CAViiLRY 

Enciphering Alphabet 

Plain .«BGDSFGHIJKLL:NOPgRSTUV ;X 
Gipher. GHIJKLMH0PQRSTUVV/XYZA3GD 

Encipherment 

Plain text. REPEL INVAD INGGA VALR 

Cryptogram. XKVKR oTBGJ OTMIG BGRX 

Cryptogram 

Xi:vi:r otbgj otiIig bgrxs 

(3) The enciphering alphabet sho'm above represents a 
case wherein the sequence of letters of both components 

of the cipher alphabet is the normal sequence, with the 
sequence forming the cipher component merely shifted six 



W 1?J K 



_ ^_F ID : A64644 

intervals in retard (or 20 intervals in advance) of the 
position it occupies in the normal alphabet. If, there- 
fore, t'vo strips of paper bearing the letters of the 
normal sequence equally spaced are regarded as the two 
components of the cipher alphabet and are. juxtaposed 
at all of the 2o possible points of coincidence that 
/Leld direct standard cipher alphabets, it is obvious 
that one of these 25 juxtapositions must correspond to 
the actual juxtaposition shor/n in the enciphering alpha- 
bet directly above. ^ It is equally obvious that if a 
rocQrd were kept of the results obtained by applying 
the values given at each juxtaposition to the letters 
of the cryptogran, one of these resulto would yield 
the plain text of the cryptogran. 

(4) Let the work be systematized and the results 
set down in an orderly manner for examination. It is 
obviously unnecessary to juxtapose the two ooriponents 
so that Aq = Apj for on the assumption of a direct 
standard alphabet, juxtaposing two direct nonal com- 
ponents at their normal point of coincidence merely 
yields plain text. The next possible juxtaposition, 
therefore, is A = 3_. Let the juxtaposition of the 
two sliding strips therefore be Ag = 3p, as shown heres 

rlain . ABCD3FGIII JKLiHOP:jilSTUV\VXf Za3GD.3FGHlJiai INOP'.'RSTUV^/XSfZ 
Cipher* .iBCDjSFGHIJKL N0P"'JRCTUV /X/Z 

The values given by this juxtaposition are substituted 
for the first 15 letters of the cryptogram and the 
following results are obtained* 

Cryptogr am. .- X K V K R 0 T B G £ _0 T ui I G 3 jG R X B 

1st Test - "Plain text" - Y L W L *S P U G H K~ p’lf II J H C h"s Y F 

This certainly is not intelligible text, obviously, 
the two components were not in the position indicated 
in this first test. The cipher component is therefore 
slid one intsrval to the •."i'^at, making A^ = Cp, and a 
second test is made. Thus. 

Plain . ABCDBFGilIJkLi.NuP^R5TUWXYZiiBC£)BFGrfIJKIi..N0P jRSTUV XYZ 
Ciphe r AJC j JF .+ II I.;.. ;iOr ITSTUY /XYZ 

Cryptogram. .X JUiL 0 T 3 G J 0 T id I G 3 G R X 3 

2d Test - "rlain text" - Z li X* li f '(T V D I L '> V “o 'if I “'“j I T Z G 

Neither does the second test result in disclosing any 
plain text. But, if the results pf the two tests are 
studied a phenomenon that at first seems quite puzzl- 
ing comes to light. Thus, suppose the results of the 
two tests are superimpos ed in this fashion. 

^ One of the st ’ips shoula bea ' the sequence repeated. This allo\ s for 
juxtaposing the two saquences at any of the 26 possible points of coinci- 
dence so as to have a complete cipher alphabet sho'lng at all ti.ies. 



REF ■ ^ ^ ^ ^ 



C rvptoTr am. K V_KR 0 T B S J 0 T 1 1 JE G 3 G R X E 

1st Test - "Plain text" -YLWLS 'PUCHK PUNJH CHSYP 

2nd Test - "Jrlain text" - ZMXMT QVDIL QVOKI DITZG 

(5) Note vhat has happened. The net result of the two 
experiments was merely to continue the normal sequence be^un 
by the cipher letters at the heads of the several c olumns . 

It is obvious that if. the normal sequence is completed in 
each column the results will be exactly the same as though 
the whole set of 25 po ssib le tests _ha^ actually been per- 
formed « Let the columns therefore be completed, as shovm 
in Fig. 11. 



X 


K 


V 


K 


R 


0 


T 


B 


G 


J 0 


T 


il 


I 


G 


B 


G 


R 


X 


E 


Y 


'l' 


V/ 


L 


S 


P 


U 


G 


H 


K P 


U 


N 


J 


H 


G 


h" 


s' 


'y 


‘f 


Z 


M 


X 


ii 


T 




V 


D 


I 


L Q 


V 


0 


K 


I 


D 


I 


T 


z 


G 


A 


N 


Y 


N 


U 


R 


U 


E 


J 


H R 


YJ 


P 


L 


J 


E 


J 


U 


A 


H 


3 


0 


Z 


0 


V 


S 


X 


F 


i: 


H S 


•\r 


Q 


I* 


K 


F 


K 


V 


B 


I 


C 


P 


A 


P 


\f 


T 


Y 


G 


L 


0 T 


Y 


R 


N 


L 


G 


L 


V 


G 


J 


J 


■1 


B 


T 

% 


X 


U 


Z 


H 


L 


P U 


Z 


S 


0 


li 


H 


ll 


X 


D 


K 


3 


R 


G 


R 


Y 


V 


A 


I 


H 


i V 


A 


T 


P 


11 


I 


N 


Y 


E 


L 


F 


S 


D 


S 


Z 


\I 


D 


J 


0 


R M 


B 


U 


Q 


0 


J 


0 


Z 


F 




G 


T 


3 


T 


A 


X 


G 


K 


P 


S X 


G 


y 


R 


P 


K 


P 


A 


G 


N 


H 


U 


F 


U 


3 


Y 


J 


L 


Q 


T Y 


D 


V/ 


S 


Q 


L 


0 


'B 


H 


0 


I 


V 


G 


V 


G 


Z 


E 


M 


R 


U Z 


E 


X 


T 


R 


U 


R 


G 


I 


P 


J 


\t 


H 


U 


D 


A 


F 


H 


S 


V A 


F 


Y 


U 


6 


N 


S 


D 


J 


Q 


K 


X 


I 


X 


E 


B 


G 


0 


T 


B 


G 


z 


V 


T 


0 


T 


E 


K 


R 


L 


Y 


J 


Y 


F 


G 


II 


P 


U 


X G 


H 


A 


Yif 


U 


P 


U 


F 


L 


S 


L 


Z 


K 


Z 


G 


D 


I 


Q 


V 


Y D 


I 


B 


X 


V 


1 


V 


G 


d 


T 


N 


A 


L 


A 


H 


E 


J 


R 




Z 3 


J 


c 


Y 


W 


R 


¥ H 


N 


U 


.0 


B 


M 


B 


I 


F 


K 


S 


X 


A F 


K 


D 


Z 


X 


S 


X 


1 


0 


V 


. P 


G 


W 


G 


J 


G 


L 


.T 


Y 


B G 


L 


E 


A 


Y 


T 


Y J 


P 


vl 




D 


0 


D 


K 


H 




U 


Z 


G H 


M 


F 


B 


Z 


U 


Z 


K 




X 


* R 


3 


P 


T 

ill 


L 


I 


N 


V 


A 


J I 


N 


G 


G 


A 


V 


A 


L 


R 


Y 


S 


F 


Q 


F 


11 


J 


0 


:/ 


B 


E J 


0 


H 


D 


B 


J 


B 


M 


S 


Z 


T 


G 


R 


n 

VT 


.1 


K 


P 


X 


G 


F K 


P 


I 


E 


C 


X 


G 


N 


T 


A 


U 


H 


S 


H 


0 


L 


Q 


Y 


D 


G L 


'i 


J 


F 


D 


Y 


D 


0 


U 


B 


V 


I 


T 


I 


P 


ii'i 


R 


z 


E 


H M 


R 


K 


G 


E 


Z 




P 


y 


G 




J 


U 


J 


i 


N 


S 


A 


FINS 
Fig. 11 


L 


H 


F 


A 


F 


Q 


’.7 


D 



An examination of the successive horizontal lines of the 
diagram discloses one and only one line of plain text, 
that marked by the asterisk and reading R S P E L I N 
V A D I N G C A V A L R Y. 

(6) Since each column in Fig. 11 is nothing but a 
normal sequence, it is obvious that instead of labori- 
ously v/riticT down these columns of letters every time 
a cryptogram is to be examined, it would be more conven- 
ient to prepare a sbt of strips each bearing the normal 
sequence doubled (to permit complete coincidence for an 



REF ID:A64644 

- 44 - 

entire alphabet at any setting;, and have them available 
for exaiiniiij any future crypto-yraas. In using such a 
set of sliding strips in order to solve a crypt 0^,-rain 
prepared by means of a single direct standard cipher 
alphabet, or to make a test t'o detemine -hether a 
cryptogra.? has bepn so prepared, it is only necessary 
to "set up" the letters of the cryptogram on the strips, 
that is, align them in a single row across the strips 
(by sliding the individual strips up or do\m) . The 
successive horizontal lines, called gen era tric es 
(singular generatri x) < are then examined in a search 
for intelligible text. If the cryptogram really belongs 
to this simple type of cipher, one of the generatrices 
will exhibit intelligible text'all the way across; 
this text will practically invariably be the plain text 
of the message. This method of analysis may be termed 
S. so lut ion by comple ti ng the plain-component sequenc e. 
Sometimes it is referred to as "running down” the se- 
quence. The principle upon which the method is based 
constitutes one of the cryptanalyst's most valuable 
tools. 

b. The case of reversed standard alphabets . - 

(1) The lethod described under subpar. a may also 
be applied in slightly modified form, in the case of a 
cryptogram enciphered by a single reversed standard 
alphabet. The basic principles are identical in the 
two cases. 

(2) To show this it is necessary to experiment with 
two sliding components as before, except that in this 
case one of the components must be a reversed normal 
sequence, the other, a direct normal sequence." 

(3) Let the two components be .iuxtaposed A to A, 
as shown below, and then let the resultant values be 
substituted for 'the letters of the cryptogram. Thus. 

Cryptogram 

rCRCV YTL. CD YTA3G LCVl'I 

r'lain . ABCD3FGHIJKLl!iW?"JASTUWXfZABCJJi7GHIJKIijiD0P^RSTUV\/XYZ 
Cipher: ZYX’./VUTSR^JiONMLKJIilGFSDCBA 



It is recommended that the student prepare a set of 25 strips x 
X 15", made of well-seasoned wood, and glue alphabet strips to the 
wood* The alphabet on each strip should be a double or repeated alpha- 
bet with all letters equally spaced, so as to permit of coincidence 
throughout a complete alphabet. 



45 



Cryptogra m 

1st Test - "ilain text" 



V## 

- “l i j ”y f c h’ f u X ‘ 



Y T .i i! G 



G H A V/ U P U F L S 



(4) This does not yield intelligible text, and 
therefore the reversed component is slid one space 
for'/ard and a second test is made. Thus. 

Plain . A3CjDIi;FGiiIJKLl.JIOPQRSTUV'/XYZA3CDi:FGHIJi:Li.H0PQRSTUV./XYZ 
Ci pho r ■. ZYX’ miTbX ^POli liZJIHGF'JJDCBA 



_ O r yptogram 



PCRCV YTLGD YTa3G LGVPI 



2d Test - "i-lain tex,t" -1.1 ZKZG DI^VY JI3XV ';VGMT 

(5) I'leither does the second test yield intelligible text. 
But let the results of the two tests be superimposed. Thus. 



Cryptogram 



-PGRt3V YTLGi) Y T A 3 G 



Lr 



V P I 



1st Test - "Plain text"* - L Y J Y F C H "p U 'x ~ C H .A U' V U F L S 

2nd Test - "Plain text" -i. ZKZG DI'iVY DIBXV QVGMT 

(6) It is seen that the letters of the "plain text" 
given by the seco nd trial are merely the continuants of 
the normal sequences initiated by the letters of the 
"plain text" given by the first trial. If these sequences 
are "run dov/n", that is, completed within the columns, the 
results must obvioysly be the same as though successive 
tests exactly similar to the first tv;o were applied to the 
cryptogram, using one reversed normal and one diPect 
noriaal component. If the crypto |ram has really been pre- 
pared by ui’ans of a single reversed standard alphabet, one 
of the generatrices of the diagrain that results from com- 
pleting the sequences uiust yield intelligible text. 

(7) Let the diagram be made, or. better yet, if the 
student has already at hand the set of sliding strips 
referred to in the footnote to page 44, let him "set up" 
the letters given by the first trial. Fig. 12 shows the 
dia'^ram and indicates the plain-text generatrix. 



ID:A64644 



p 


C 


R 


G 


X 


Y T 


_L 


G 


_D 


X 


T 


AEG 


L 


G 


X 


p 


I 


-L 


Y 


J 


Y 


F 


G 


H 


p' 


u'' 


A 


g" 


H 


A 


1 u 


P 


u" 


F 


L 


S 


i .. 


z 


K 


Z 


V7 


D 


I 


Q 


V 


Y 


B 


I 


3 


X V 


■) 


V 


G 


M 


T 


N 


A 


L 


A 


H 


S 


J 


R 


I 


Z 


3 


J 


G 


Y 7 


R 


'/ 


H 


il 


U 


0 


3 


LL 


B 


I 


F 


K 


S 


X 


A 


F 


K 


D 


Z X 


S 


X 


I 


0 


V 


P 


G 


N 


C 


j 


G 


L 


T 


Y 


B 


G 


L 


3 


A Y 


T 


Y 


J 


P 


T 

.i 




D 


0 


D 


K 


H 


I'l 


U 


Z 


G 


H 


H 


F 


B Z 


U 


Z 


Iv 




X 


* R 


3 


P 


3 


L 


I 


II 


V 


A 


D 


I 


N 


G 


C A 


V 


A 


L 


R 


Y 


‘ & 


F 


3 


F 


Li 


J 


0 


7 


3 


3 


J 


0 


H 


D B 


J 


B 


U 


S 


Z 


T 


G 


R 


G 


N 


K 


p 


X 


G 


F 


K 


P 


I 


E C 


X 


G 


N 


T 


A 


U 


H 


S 


H 


0 


L 


i 


Y 


D 


G 


L 


Q J 


F D 


Y 


D 


0 


U 


B 


V 


1 


T 


I 


P 




R 


Z 


3 


H 




R K 


G E 


Z 


3 


P 


V 


G 


7 


J 


U 


J 




N 


S 


A 


F 


I 


N 


S 


L 


H F 


A 


F 


Q 


7 


D 


X 


K 


V 


K 


R 


0 


T 


B 


G 


J 


0 


T 


h 


I G 


3 


G 


R 


X 


E 


. y 


L 


7 


L 


S 


P 


U 


G 


H 


K 


P 


U 


H 


J H 


G 


H 


5 


Y 


F 


z 


LI 


X 


LI 


T 


'1 


V 


G 


I 


L Q 


V 


0 


K I 


B 


I 


T 


Z 


G 


A 


N 


Y 


N 


U 


R 


7 


3 


J 


M 


R 


'/ 


P 


L J 


3 


J 


U 


A 


H 


B 


0 


Z 


0 


V 


S 


X 


F 


K 


N 


S 


X 


T 


M K 


F 


K 


V 


B 


I 


G 


P 


A 


P 


'/ 


T 


Y 


G 


L 


0 


T 


Y 


R 


N L 


G 


L 




0 


J 


D 


'i 


B 




X 


U 


Z 


H 


M 


P U 


Z 


S 


0 H 


H 


M 


X 


D 


K 


E 


R 


G 


R 


Y 


V 


A 


I 


N 




■V 


A T 


P N 


I 


N 


Y 


3 


L 


F 


S 


D 


S 


Z 


\1 


B 


J 


0 


R 




3 


U 


Q 0 


J 


0 


Z 


F 


M 


G 


T 


3 


T 


A 


X 


G 


K 


P 


S X 


C 


V 


R P 


K 


P 


A 


G 


N 


H 


U 


F 


U 


B 


Y 


D 


L 


1 


T 


Y 


B 


r 

/ 


S i 


h 




B 


H 


0 


I 


V 


G 


V 


G 


Z 


3 


A 


R 


U 


Z 


3 


X 


T R 


II 


R 


C 


I 


P 


J 


/ 


H 


t 


D 


A 


F 


H 


S 


V 


A 


F 


y 


U S 


N 


S 


B 


J 


Q 


K 


X 


I 


X 


3 


B 


G 


0 


T 


7 


B 


G 


z 


V T 


0 


T 


IS 


K 


R 



Fig. 12 



(3) The only difference in procedure between this 
case and the preceding one (\/here the cipier alphabet 
was a direct standard alphabet) is that the letters of 
the cipher text are first "deciphered" by ueans of any 
reversed standard alphabet and then the columns are 
"run down" according to the normal ABC...Z sequence. 

For reasons ’.vhich will become apparent very soon, the ■ 
first step in this method is called "converting the 
cipher lett'--rs into their plain-component equivalents"; 
the second step is the same as before "completing the 
plain-component sequences". 

21. Special remarks on the method of solution by co’-pleting the plain- 
component sequence. - a. The terms employed to designate the steps in the 
solution set forth in jHar. 20 b, viz., "converting the cipher letters into 
their plain-component equivalents" and "completing the plain-corai’'onent se- 
quence", accurately describe the process. Their meaning will become more 
clear as the student progresses with the work. It may be said that when- 
ever the plain component of a cipher alphabet is a knov/n sequence, the dif- 
ficulty and time required to solve any cryptogram involving the use of that 
plain component is practically cut in half. In some cases this knowledge 
f acilitates and in ot her case s is the only th in; th at m akes possible the 
solution of a very sho r t cryptogram that mi:;ht ot he rT,jise defy solution . 



REF ID:A64644 

A n t 



Later on an example will be 3iven to illustrate \vhat is meant in this 
regard. 



I , 

b. The student should' take note, however, of two qualifying expres- 
sions that were employed in a preceding paragraph to describe the results 
of the application of the method. It was stated that "one of the gener- 
atrices will exhibit intelligible text a ll th e way a cr oss '; thid text v/ill 
p ractica l ly in variably be the plain text". ^ill there ever be a case in 
which r.ore than one generatrix will yield intelligible text throughout 
its extant ^ That obviously depends almost entirely on the number of let- 
ters that are aligned to form a generatrix. If a generatrix contains but 
a very fev/ letters, only five, for example, it may happen as a result of 
pure chance that there ’7ill be two or more generatrices shoring what 
might be "intelligible text", ilote in Fig. 11, for example, that there 
are several cases in --'hich 3-letter and 4-let ber English words (/ilif, VAIN, 
'JOT, TIP, etc.) appear on generatrices that are not correct, these words 
being formed by pure chance, dut there is not a single case, in this 
diagram, of a 5-letter or longer v/ord appearing fortuitously, because ob- 
viously the longer the word the -smaller the probability of its appear- 
ance purely by chance; and the probability that two generatrices of 15 
letters each will both yield intelligible text along their entire length 
is exceedingly remote, so remote, in fact, that in practical cryptography 
such a case may be considered nonexistent.^ 

c. The student should observe that in reality there is no difference 
whatsoever in principle between the two methods presented in subpars. a 
and b of Par. 20. In the former the preliminary step of converting the 
cipher letters into their plain-component equivalents is apparently not 
present but in reality it is there. The reason for its apparent absence 

is that in that case the plain component of the cipher alphabet is identical 
in all respects with the cipher component, so that the cipher letters re- 
quire no conversion, or, rather, they are identical with the equivalents 
that would result if they were converted on the basis = Ap. In fact, 

if the solution process had been arbitrarily initiated by converting the 
cipher letters into their plain-component eauivalents at the setting A = 
liip, for exaiple, and the cipher component slid one interval to the right 
thereafter, the results of the first and second tests of Par. 20 a would 
be this. 

Cryptogr am. - XKVKROTBJJOT.il J B G R X S 

1st Test - "-Plain text" - LfJ/FCHPUXOHA >‘UPUFLS 
2nd Test - "ilain text" -i,. ZKZGHITVYOIBXVqVJMT 

Thus, the foregoing- diagram duplicates in every particular the d-iagram re- 
sulting from the first two tes-bs under Par. 20 a- a first line of cipher 
letters, a second line of letters derived from them but showing externally 
no relationship with the first line, and a third line derived immediately 
from the second line by continuing the direct normal sequence. This point 

^ A person with patience and an inclination toward the curiosities of the 
science -aight construct a text of 15 or more letters which would yield tw# 
"intelligible" texts on the plain-cor.ponent completion diagram. 



REF ID:A64644 

4:3 - 



is brought to attention only for the purpose of showin-; that a single, 
broad principle is the basis of the general method of solution by complet- 
ing the plain-compnnsiit sequence, and once the student has this firmly in 
mind he will have no difficulty whatsoever in realizing when the principle 
is applicable, what a powerful cryptanalytic tool it can be, and what re- 
sults he may expect from its application in specific instances. 

d. In the two foregoing examples of the application of the principle, 
the plain component was a normal sequence but it should' be clear to the 
student, if he has grasped what has been said in the preceding subpara- 
graph,, that this component may be a mixed sequence v/hich if known (that is, 
if the sequence of letters comprising the sequence is knov/n to the crypt- 
analyst) can be handled just as readily as can a plain component, that is a 
normal sequence. 

e. It is entirely immaterial at what points the plain anJ the cipher 
components are .juxtaposed in the preliminary step of converting the cipher 
letters into their plain-component equivalents. For example, in the case 
qf the reversed alphabet cipher solved in i-'ar. 20 b, the two components 
urere arbitrarily juxtaposed to give the value A = A, but they might have 
been juxtaposed at any of the other 25 possible points of coincidence 
without in any way affecting the final result, viz., the production of one 
plain-text generatrix in the completion diagram. 

22. Value of mechanical solution as a short cut. a. It is obvious 
that the very first step the student should take in his attempts to solve 
an unknown cryptogram that is obviously a substitution cipher is to try 
the mechanical method of solution by completing the plain-component se- 
quence, using the normal alphabet, first direct, then reversed. This takes 
only a very few minutes and is conclusive in its results. It saves the 
labor and trouble of constructing a raonoliteral- frequency distribution in 
case the cipher is of this simple type. Later on it will be seen how cer- 
tain variations of this simple type may also be solved by the application 
of this method. Thus, a very easy short cut to solution is afforded, which 
even the experienced cryptanalyst never overlooks in his first attack on an 
unknown cipher. 

b. It is i.iportant nov/ to note that if neither o f th e two foregoing 
attempts is successful in bringing plain text to li :ht and the cryptogram 
is quite obviously mon oalphabetic i_n_ character, the crypt ana lyst is war - 
ranted in assuming that the crvp-^ojram involves a mixed ci pher alphabet 7 ^ 
The steps to be taken in attacking a cipher of the latter type will be 
discussed in the next section. 



There is but one other possibility, already referred to under i-ar. 17 d, 
which involves the case where transposition and monoalphabetic substitu- 
tion processes have 'leen applied in successive steps. This is unusual, 
however, and will be discussed in its proper place. 



REF ID : A64644 

* 

- <t7 •• 

S3CTI0N VI 

b'JJSTITUi’IUlJ .ITH CIrHLM I'JjFiiAdSIQ 

Paragraph 

Basic reason for the low degree of cryptographic security 

afforded by inonoalphabetie cryptograms involving standard 



cipher alphabets 23 

Prelimin^.ry steps in the analysis of a monoalphabetic, mixed- 

alphabet cryptogram. ........... .... 24 

Further data concerning normal plain text . 25 

Preparation of the work sheet ........... 26 

Triliteral-frequency distributions. ....... 2? 



Classifying the cipher letters into vowels and consonants .... 28 



Further analysis of the letters representing vowels and 

. consonants 29 

Substituting deduced values in the cryptogram .......... 30 

Completing the solution 31 

General remarks on the foregoing solution . 32 

The "probable-word" method 5 its value and applicability 33 

V,. . 

Solution of additional cryptograms produced by the same cipher 

component % 34 



23. Basic reason for the low degree of cryptographic security afforded 
by monoalphabetic cryptograms involving standard cipher alphabets. - a. The 
student has seen that the solution of monoalphabetic cryptograms involving 
standard cipher alphabets is a very easy matter. Two methods of analysis 
were described, one involving the construction of a frequency distribution, 
the other not requiring this kind of tabulation, being almost mechanical in 
.nature and correspondingly rapid. In the first of these two methods it was 
necessary to make a correct assumption as to the value of .but one of the 26 
letters of the cipher alphabet and the values of the remaining 25 letters 
become at once known; in the second method it was not necessary to assume a 
value for eveii a single cipher letter. The student, -should understand what 
constitutes the basis of this situation', the fact that the two components 
of the cipher alphabet are composed of known fieouences . ./hat if one or 
both of these components are, for the cryptanalyst, unknown sequences .^ In 
other words, what difficulties will confront the cryptanalyst if the cipher 
component of the cipher alphabet is a mixed sequence? './ill such an alpha- 
bet be solvable as a whole at one stroke, or v/ill it be necessary to solve 
its values individually? Since the determination of the value of one cipher 



REF ID:A64644 

• 50 - 



letter in this case gives no direct clues to the value of any other letter, 
4-t would seem that the solution of such a cipher should involve consider- 
ably more analysis and experinent than has the solution of either of the 
■two types of ciphers so far examined occasioned. A typical example will 
be studied. 



24. Preliminary steps in the analysis of a monoalphabet ic , mixed 
alphabet cryptogram.’- a. llote the following cryptogram: 



8FDZF 


lOGHL 


PZFGZ 


DYSPF 


H3ZDS 


GVHTF 


UPLVD 


FGYVJ 


VFVHT 


GADZZ 


AIT YD 


Zfl’ZJ 


ZTGPT 


'nZ3D 


VFHTZ 


GFXSB 


GIdZY 


VTXOI 


YVT3F 


VliGZZ 


THLLV 


XZ]^ 


HTZaI 


TYJZY 


3DVFH 


"tzgfk 


ZDZZJ 


SXISG 


ZYGAV 


FSLGZ 


DTHHT 


CJZRS 


VTYZD 


OZFFH 


TZAIT 


YDZYG 


AVJGZ 


ZTICHI 


TYZYb 


gzg:iu 


ZFZTG 


UPGJI 


X fGHX 


ASRUZ 



^UIJ JIGIHTV 3AGXX 

/ 

b. A casual inspection of the text discloses the presence of several 
long repetitions as well as of many letters of no'rmally low frequency, such 
gs F, G, V, X, and Z; on the other hand, letters of normally high frequency, 
such as the vowels, and the consonants ii and R, are relatively scarce. The 
cryptogram is obviously a substitution cipher^ and the usual mechanical tests 
for determining whether it is possibly of the monoalphabetic , standard -alpha- 
bet type^ are applied. The results being negative, ■the monoliteral-frequency 
distribution is immediately constructed and is as shown in Fig. 13. 




A3CD3FGHIJKLLIN0PTRSTUV’/xyZ 
8 4 1 23 3 19 19 15 10 3 2 5 2 0 3 5 6 2 10 22 5 16 1 8 14 35 

Fig. 13 



£. The fact that the monoliteral-frequency distribution shows very 
marked crests and troughs means that the cryptogram is undoubtedly monoalpha- 
betic; the fact that it has already been tested (by the method of complet- 
ing the plain-component sequence) and found not to be of the monoalphabetic, 
standard -alphabet type, indicates with a high degree of probability that it 
involves a mixed cipher alphabet, A feiff moments might be devoted to making 
a careful inspection of the monoliteral-frequency distribution to insure that 
it cannot be made to fit the normal; the object of this v/ould be to rule out 
the possibility that the text resulting from substitution by a standard cipher 



^ Par. 13 f, s, above. 


* 


2 

Pars. 20 - 22, above. 






REF_ IP : A64644 

alphabet had not subsequently been transposed. But this inspection in this 
case is hardly necessary, in viev of the presence of long repetitions in 
the message.^ (See Par. 13 g. ) 

d. One aipjht, of course, attempt to solve the cryptogram by applying 
the simple principles of frequency. One might, in other words, assume that 
Zg (the letter of greatest frequency) represents iS _5 (the letter of next 
greatest frequency) represents and so on. If the message vrere long 
enough this simple procedure might more or less quickly give the solution. 
But the message is relatively short and many difficulties would be encoun* 
tered, lluch time and effort would be expended unnecessarily, because it is 
hardly to be expected that in a message of only 235 letters the relative 
order of frequency of the various cipher letters should exactly coincide 
v/ith, or even closely approximate the relative order of frequency of let- 
ters of normal plain text found in a count of 50,000 letters. It is to be 
emphasized that the beginner must repress the natural tendency to place 
too much confidence in the generalized principles of frequency and to rely 
too much upon them. It is far better to bring into effective use certain 
other data concerning normal plain text which thus far have not been brought 
to notice. 



25. Further data concerning normal plain text. - a. Just as the in- 
dividual letters constituting a large volume of plain text have more or 
less characteristic or fixed frequencies, so it is found that digraphs and 
trigraphs have characteristic frequencies, when a large volume of text is 
studied statistically. In Appendix 1, Table 1 are shown the relative fre- 
quencies of all digraphs appearing in the 260 telegrams referred to in 
Paragraph 9 e. It will be noted that 546 of the 676 possible pairs of let- 
ters occur in these telegrams, but whereas many of them occur but once or 
twice, there are a feiv which occur hundreds of times. 

j^. In Appendix 1 will also be found several other kinds of tables and 
lists which \;ill be useful to the student in his work, such as the relative 
ortler of frequency of the 50 digraphs of greatest frequency, the relative 
order of frequency of doubled letters, doubled vowels, doubled consonants, 
and so on. It is suggested that the student refer to this appendix now, to 
gain an idea of the data available for his future reference. Just how these 
data may be employed will become apparent very shortly. 

26. Preparation of the work sheet. - a. The details to be considered 
in this paragraph may at first appear to be superfluous but long experience 
has proved that systematization of the work, and preparation of the data in 
the most utilizable, condensed fora is most advisable, even if this takes 



^ This possible step is mentioned here for the purpose of making it clear 
that the plain-component sequence completion method cannot solve a case in 
which transposition has followed or preceded raonoalphabetic substitution 
with standard alphabets. Gases of this kind will be discussed in a later 
text. It is sufficient to indicate at this point that the frequency dis- 
tribution for such a combined substitution-transposition cipher would pre- 
sent the characteristics of a standard alphabet cipher - and yet the method 
of completing the plain-component sequence vrould fail to bring out any 
plain text. 



REF ID:A64644 

52 - 



some timso In the first place if it merely serves to avoid interruptions 
and 'irritations occasioned by failure to have the data in an instantly 
available form, it ’.vill pay by saving mental ./ear and tear. In the second 
place, especially in the case of complicated cryptograms, painstaking care 
in these details, while it nay not always bring about success, is often 
the factor that is of greatest assistance in ultimate solution. The de- 
tailed preparation of the data may be irksome to the student, and he may 
be tempted to avoid as much of it as possible, but, unfortunately, in the 
early stages of solving a erj/ptograra he does not hnov/ (nor, for that mat- 
ter, does the expert alv/ays know) just v/iiich data are essential and v'hich 
may be neglected. Even though not all of the data may turn out to have 
been necessary, as a general rule, time is saved in the end if all the 
usual data are prepared as a regular preliminary to the solution of most 
cryptograms. 

b. First, the cryptogram is recopied in the ford of a work sheet. 

This sheet should be of a good quality of paper so as to withstand con- 
siderable erasure. If the cr/’pto^ran is to be couied by hand, cross-sec- 
tion paper of p" squares is extremely useful. The ./riting should be in 
ink, and plain, carefully made roman capital letters should be used in all 
cases. If the crypto -^ram is to be copied on a typewriter, the riboon em- 
ployed should be impregnated with an inx that will not smear or smudge 
under ths hand. 

c. The arrangement of the characters of the cryptogram on the work 
sheet is a matter of considerable importance. If the cryptogram as first 
obtained is in groups of regular length (usually five characters to a 
group) and if the monoliteral-frequency distribution shows the cryptogram 
to be monoalphabetic , the characters should be copied ’./ithout regard to 
this grouping. It is advisable to allow one space between letters, and 

to v/rite a constant number of letters per line, approximately 25. At least 
two spaces, preferably three spaces should be left between hoi'izontal lines. 
Care should be taken to avoid cro-vding the letters in any case, for this is 
not only confusing to the eye but also mentally irritating when later it is 
found that not enoug'n space has been left for making various soidis of marks 
or indications. If the cryptogram is originally in what appears to be word 
lengths (and this is the case as a rule only with the cryptograms of suna- 
teurs), naturally it should be copied on the work sheet in the original 
groupings. If furthor study of a cryptogram sho\'s that some special group- 
ing is required, it is best to recopv it on a fresh v/ork stieet rather than 
to attempt to indicate the new grouping on the old \/ork sheet. 

d. In order to be able to locate or refer to specific letters or 
groups of letters with speed, certainty, and \’ithout possibility of con- 
fusion, it is advisable to use coordinates applied to the lines' and colamns 
of the text as it appears on the v/ork sheet. To rainiaize possibility of 
confusion, it is best to appl/ letters to the horizontal linos of the text, 
numbers to the vertical columns. In referring to a letter the horizontal 
line in which the letter is located is usually given first. Thus, referring 
to the work sheet shovm below, coordinates A17 designate the letter Y, the 
17th letter in the first line. The letter I is usually ojiitted from the 
series of line indicators, so as to avoid confusion with the figure 1. If 



REF ID:A64644 

- 53 - 

lines are limited to 25 letters each, then each set of 100 letters of the 
text is automatically blocked off by remembering that 4 lines constitute 
100 letters. 

e. Above each character of the cipher text may be some indication 
of the frequency of that character in the whole cryptogram. This indica- 
tion may be the actual number of times the character occurs, or, if colored 
pencils are used, the cipher letters may be divided up into three cate- 
gories or groups- high frequency, medium frequency, and low frequency. 

It is perhaps simpler, if clerical help is available, to indicate the 
actual frequencies. This saves constant reference to the frequency tables, 
which interrupts the train of thought, and saves considerable time in the 
end. 

f. After the special frequency distribution, explained in ihr. 27 
below, has been constructed, repetitions of digraphs and trigraphs should 
be underscored. In so doing, the student should be particularly watchful 
of trigraph repetitions v;hich can be further extended into tetragraphs 
and polygraphs of greater length. Repetitions of more than six or seven 
characters should be set off by heavy vertical lines, as they indicate 
repeated phrases and are of considerable assistance in solution. Revers- 
ible digraphs should also be indicated by an underscore with a loop in 
it. Anything which stri :es the eye as being peculiar, unusual, or sig- 
nificant as regards the distribution or recurrence of the characters 
should be noted. a 11 these marks should, if convenient, be made with ink 
so as not to cause smudging. The work sheet v/ill nov/ appear as shown 
herewith- 





1 


2 


3 


4 


5 


6 


7 


8 


9 


10 


11 


12 


13 


14 


15 


16 


17 


18 


19 


20 


21 


22 


23 


24 


25 




10 


19 


23 


35 


19 


10 


3 


19 


15 


5 


5 


35 


19 


19 


35 


23 


14 


10 


5 


19 


15 


4 


35 


23 


10 


A. 


S 


F 


D 


Z 


F 


I 


0 


G 


H 


L 


P 


Z 


F 


G 


Z 


D 


Y 


S 


P 


F 


H 


B 


Z 


D 


S 




19 


16 


15 


22 


19 


5 


5 


5 


16 


23 


19 


19 


14 


16 


3 


16 


19 


16 


15 


22 


19 


8 


23 


35 


35 


B. 


G 


V 


H 


T 


F 


U 


F 


L 


V 


D 


F 


G 


Y 


V 


J 


V 


F 


V 


H 


T 


G 


A 


D 


Z 


Z 




8 


10 


22 


14 


23 


35 


14 


19 


35 


3 


35 


22 


19 


5 


22 


16 


22 


35 


4 


23 


16 


19 


15 


22 


35 


C. 


A 


I. 


T 


Y 


J 


Z 


Y 


F 


Z 


J 


Z 


T 


G 


F 


T 


V 


T 


Z 


B. 


D 


V 


F 


H 


T 


Z 




23 


19 


8 


10 


4 


19 


10 


23 


35 


14 


16 


22 


8 


3 


10 


14 


16 


22 


3 


19 


16 


2 


19 


35 


35 


D. 


D 


F 


X 


S 


3 


G 


I 


D 


Z 


Y 


V 


T 


X 


, 0 


I 


Y 


V 


T 


3 


F 


V 


M 


G 


Z 


Z 




22 


15 


5 


5 


16 


8 


35 


23 


19 


2 


15 


22 


35 


8 


10 


22 


14 


23 


35 


14 


4 


23 


16 


19 


15 


3. 


T 


H 


L 


L 


V 


X 


L 


D 


F 


ii 


H. 


T 


Z 


A 


I 


T 


Y 


D 


Z 


Y 


B. 


D 


V 


F 


H 




22 


35 


23 


19 


2 


35 


23 


35 


35 


3 


10 


8 


10 


10 


19 


35 


14 


19 


8 


16 


19 


10 


5 


19 


35 


F. 


T 


Z 


jD 


F 


K 


Z 


D 


Z 


Z 


J 


S 


X 


I 


S 


G 


Z 


Y 


G 


A 


V 


F 


5 


L 


G 


Z 




23 


22 


15 


15 


22 


1 


23 


35 


2 


10 


16 


22 


14 


35 


23 


3 


35 


19 


19 


15 


22 


35 


8 


10 


22 


G. 


D 


T 


H 


H 


T 


C 


i) 


Z 


R 


S 


V 


T 


Y 


Z 


D 


0 


Z 


F 


F 


H_ 


T 


Z 


A 


I 


T 




14 


23 


35 


14 


19 


8 


16 


23 


19 


35 


35 


22 


2 


15 


10 


22 


14 


35 


14 


10 


23 


35 


19 


15 


5 


H. 


Y 


D 


Z 


Y 


n 

\j 


A 


V 


p 


G 


Z 


Z 


T 


K 


H 


I_ 


T 




Z 


Y 


S 


D 


Z 


G 


H 


U 




35 


19 


35 


22 


19 


5 


5 


19 


23 


10 


8 


1 


19 


15 


8 


8 


10 


2 


5 


35 


23 


19 


5 


10 


23 


J. 


Z 


F 


Z 


T 


G 


U 


P 


G 


D 


I 


X 


U 


G 


H 


X 


A 


S 


R 


U 


Z_ 


D 


__F 


U 


I 


D 




3 


19 


15 


22 


16 


3 


8 


19 


8 


8 
































K. 


3 


G 


H 


T 


V 


3 


A 


G 


X 


X 

































E^F ID : A64644 



27. Triliteral-frequency distributions. - a. In what has gone before, 
a type of frequency distribution knovm as a monoliteral-frequency, bar-dis- 
tribution was used. This, of course, shows only the number of times each 
individual letter occurs. In order to apply the normal digraph and trigraph 
frequency data (given in Appendix 1) to the solubion of a cryptogram of the 
type now being studied, it is obvious that the data v;ith respect to digraphs 
and trigraphs, occurring in the cryptogram should be compiled and should be 
compared with the data for normal plain text. In order to accomplish this 
in suitable manner, it is advisable to construct a slightly more complicated 
form of distribution termed a triliteral-frequencv distribution.^ 

b. Given a cryptogram of 50 or more letters and the task of determin- 
ing what trigraphs are present in the cryptogram, there are three ways in 
v'hich the data may be arranged or assembled. One may require that the data 
show. 

(1) iiiach letter with its two succeeding letters, 

(2) 3ach letter ’,dbh its tivo preceding letters; 

(3) Each letter with one preceding letter and one 
succeeding letter. 

c. A distribution of the first of the three foregoing types nay be 
designated as a "triliteral- frequency distribution sho'dng two suffixes"; 
the second type may be designated as a "triliteral-frequency distribution 
showing two prefixes"; the third type may be designated as a "triliteral- 
frequency distribution showing one prefix and one suffix." ^uadriliteral- 
and pentaliteral-frequency distributions may occasionally be found useful. 

d. .;hich of these three arrangements is to be employed at a specific 
time depends largely upon what the data are intended to show. For present 
purposes, in connection with the solution of a monoalphabet ic substitution 
cipher employing a mixed alphabet, possibly the third arrangement, that 
showing one prefix and one suffix, is most satisfactory. 

e. It is convenient to use cross-section paper for the construction 
of a triliteral-frequency distribution in the fora of a bar-distribution 
showing crests and troughs, such as that in Figure 14. In that figure the 
prefix to each letter to be recorded is inserted in the upper half of the 
cell directly opposite the cipher letter bqing recorded; the suffix to each 
letter is inserted in the lower half of the cell directly opposite the let- 
ter being recorded; and in each case the prefix and tho suffix to the let- 
ter being recorded occupy the same cell, the prefix being directly above the 
suffix. The number in parentheses gives the total frequenc'f for each Tetter. 



Heretofore such a distribution has been termed a "trigraphic-frequency 
table". It is thought that the word "triliteral" is more suitable, to cor- 
respond with the designation "raonoliteral" in the case of the distribution 
of the single letters. The use of the word "distribution" to replace the 
word "table" has already been explained. 



KEF ID:A64644 



COiDiiiiS^D 2LSlu 0? 



UD 



Di'yraiilis 



Tri?ra'ohs 



ZS 

GV 

ZI. 

OT YD 
ZI S& 
ZI ZD 
SD HZ 



ID 

f*-n 

G-I 

SZ 

VJ 

YZ 

ZO 

oz 

ZT 

ZZ 

z? 

BY 

YZ 

ZP 

IZ 

ZP 

3V 

YZ 

AZ 

VP 

ZS 

ZY 



DZ-9 


TZ-5 


VP-4 


DZY-4 


ZD-9 


TY-5 


TO-4 


HTL-4 


H2-8 


PH-4 


ZP-4 


ITY-4 


ZY-6 


GE-4 


ZT-4 


ZDP-4 


DP-5 

GZ-5 


IT-4 


ZZ-4 


.xlT-3 



DU 

rT' 
u - 

PH 

4tl' 

VD 

Di: 

VH 

DH 

DV 

DZ 

TO 

YZ 

W 

DU 

2U 

PH 

VA ZG 
DG ZI 



□5 ?Z TP SD 



Ai; 

m 

V/H 

PD 

TU 

ZH 

DZ 

YA 

LZ 

YA 

SS 

iii 

31 

Tx-' 

2A 

?Y 

SV 

?Z 

OE 



3T 

GU' 

la 

PT 

ET 

TH- 

PT 

DT 

TL 

PT 

VT 

TO 

?B 

GL 



P.lT-i 

2YD-3 

YDZ-3 

ZAI-3 



Loti fer Polrv-;ra")hs 

HTZAITYDZY-2 
BDVPH'x LDP-2 
ZAITYDSr-3 
PHTZ-3 



LV 

Lu- 

lY 

'LI‘I 

lY 

HZ 

TO 

HO 

DE 

HZ 

lY 

xi^j 



TLi 

xiD 

ST 

AP 

DP 

LX 



UD 
















AH 


Zii 




PEI 




DX 

HT 
















YD 

XV 


VE 

T.. 




YT 

YT 


■t 


AT 
















PL 


HZ 




DP 


GX 


Ad. 
















IG 


VZ 




TT 


HA 


AT 






SG 






UG 




JX 


PV 


PI 


PH 


l\l 


OY 






LV 






GT 






ZG 


HZ 


J? 


SI 


GD 


ZS 




HL 




DZ ■ 


UL 




DG 


-lY 


D 

xXJ. 


YJ 


VZ 


AT 


ZZ 


TH 


PV 


PH 


XI 


S? 


SU 


Yx 


HG 


HZ 


LD 


TO 


PO 


vv 


PZ 


HP 


VG 


IG 


LZ 


ZS 


-P 


HP 


PP 


GH XG 


PS 



ZS 

TZ 

ZG 

TD 

TZ 

ZG 

ZB 



UP 

DG 

YY- 



DY 

n 

OP 

YD 

DH 

GD 

GY 

ZJ- 

DZ 

LD 

ID 

DY 

Ta 

XD 

ZT 

GZ 

DY 

TD 

TB 

JT 

PJ 

DY 

ZA 

DZ 

BD 

GD 

PP 

DP 



oi 

Ul 



A B 
(8) (4) 



U) (231 (31 (19)(19)(f3)(10|(3) (2) (6) (2| (Ol (3) (6| (Ol (1) (101(221 (5| (16 1 (U W (UK^l 

Pi:?. 14 



. IRF ID : A64644 

For example, in Fi;;. 14, note the prefixes an<J suffixes of the letter D s 

c 

, . FZZVAYBZIZYBZZ2CZYVSGZI 

D{23) ZYSFZZVFZFZVFZTZOZGZIFE 

f. The triliteral-frequency distribution is now to be examined v/ith 
a view to ascertaining what digraphs and trigraphs occur two or more times 
in the cryptogram. Consider the pair of lines containing the prefixes and 
suffixes to Dp in the distribution, as sho\/n directly above. This pair of 
lines shows that the following digraphs appear in the cryptogram: 



Digraphs based on prefixes Digraphs based on suffixes 



FD, 


ZD, 


ZD, 


VD, 


AD, 


YD, 


3D, 


DZ, 


DY, 


DS, 


DF, 


DZ, 


DZ, 


DV, 


ZD, 


ID, 


ZD, 


YD, 


BD, 


ZD, 


ZD, 


DF, 


DZ, 


DF, 


DZ, 


DV, 


DF, 


DZ, 


ZD, 


CD, 


ZD, 


YD, 


VD, 


SD, 


GD, 


DF, 


DZ, 


DO, 


DZ, 


DG, 


DZ, 


DI, 


ZD, 


ID 












DF, 


DE 













The nature of the tabulation in the triliteral- frequency distribution is 
such that in finding v;hat digraphs are present in the cryptogram it is im- 
material whether the prefixes or the suffixes to the cipher letters are 
studied, so long as one is consistent in the study . For example, in the 
foregoing list of digraphs based on the prefixes to D^, the digraphs FD, 

ZD, ZD, VD, etc., are found; if now, the student v;ill refer to the suffixes 
of Fp, Zp , Vp , etc., he v;ill find the very same digraphs indicated. This 
being the case, the question may be raised as to what value there is in 
listing both the prefixes and the suffixes to the cipher letters. The 
answer is that by so doing the trigraphs are indicated at the same time. 

For example, in the case of Dp, the following trigraphs are indicated* 

FDZ, ZDY, ZDS, VDF, ADZ, YDZ, BDV, ZDF, IDZ, ZDF, YDZ, BDV, ZDF, 

ZDZ, ZDT, CDZ, ZDO, YDZ, VDG, SDZ, GDI, ZDF, IDE. 

g. The repeated digraphs and trigraphs can now be found quite readily. 
Thus, in the case of D^. , examining the list of digraphs based on suffixes, 
the following repetitions are noted: 

DZ appears 9 times 
DF appears 6 times 
DV appears 2 times 

Examining the trigraphs with Dp as central letter, the following repeti- 
tions are noted: 

ZDF appears' 4 times * 

YDZ appears 3 times 
BDV appears 2 times 

h. It is unnecessary, of course, to go through the detailed procedure 
set forth in the preceding subparagraphs in order to find all the repeated 
digraphs and trigraphs. The repeated trigraphs v/ith D^. as central letter 




REF- 1D4A64644 



can be found merely from an inspection of the prefixes and suffixes op- 
posite i)j. in the distribution. It is necessary only to find those cases 
in which two or more prefixes are identical at the same time that the suf- 
fixes are identical. For example, the distribution shows at once that in 
four oases the prefix to D is at the same time that the suffix to this 
letter is Hence, the trigraph ZDF appears four times. The repeated 

trigraphs may all be found in this manner. 

i. The most frequently repeated digraphs and trigraphs are then as- 
sembled in what is termed a condensed table of repetitions , so as to bring 
this information prominently before the eye. As a rule, digraphs which 
occur less than four or five times, and trigraphs which occur less than 
three or four times may be omitted from the condensed table as being rela- 
tively of no importance in the study of repetitions. In the condensed 
table the frequencies of the individual letters forming the most important 
digraphs, trigraphs, etc., should be indicated. 

28. Classifying the cipher letters into vov/els and consonants. - a. 
Before proceeding to a detailed analysis of the repeated digraphs and tri- 
graphs, a very important step can be taken which will be of assistance not 
only in the analysis of the repetitions but also in the final solution of 
the cryptogram. This step concerns the classification of the high-fre- 
quency letters into two groups; vowels and consonants. For if the crypt- 
analyst can quickly ascertain the equivalents of the four vowels, A, S, I, 
and 0, and of only the four consonants, II, R, S, and T, he will then have 
the values of approximately two-thirds of all the cipher letters that oc- 
cur in the cryptogram; the values of the remaining’ letters can almost be 
filed in automatically. 

b. The basis for the classification will be found to rest upon a 
comparatively simple phenomenon- the associational or combinatory be- 
havior of vowels is, in general, quite different from that of consonants. 

If an examination be made of Table 7B in Appendix 1, showing the relative 
order of frequency of the 18 digraphs composing 25 per cent of English 
telegraphic text, it will be seen that the letter 3 enters into the composi- 
tion of 9 of the 18 digraphs; that is, in exactly half of all the cases the 
letter 3 is one of the two letters forming the digraph. The digraphs con- 
taining 3 are as follows; 

3D 311 SR S5 

MS RS SE T3 V3 

The remaining nine digraphs are as follows- 

AN HD OR ST 
IN NT TH 

OH TO 

None of the 18 digraphs are combinations of vowels . Note nov/ that of the 
9 combinations vdth S, 7 are with the consonants N, R, S, and T, one is 
with D, one is with V, and none is with any vo\7el . In other words, Ep com- 
bines most readily i/ith consonants but not v/ith other vowels, or even ’Ji/ith 



_ID:A64644 



itself. Using the terms often employed in the chemical analogy, S shows a 
i»reat "affinity" for the consonants U, n, S, T, but not for the vowels. 
Therefore, if the letters of highest frequency occurring in a given crypto- 
grata are listed, together 'rf-th the number of times each of them combines 
v/ith the cipher equivalent of J! , those ’.;hich show considerable combining 
pov/er or affinity for the cipher equivalent of Sp may be assumed to be the 
cipher equivalents of N, *1, Sj those which do not show any affinity for 
the cipher equivalent of Ep may be aesumed to be the cipher equivalents of 
A, I, 0, Up. Applying these principles to the problem in hand, and examin- 
ing the triliteral-frsquency distribution, ib is quite certain that = Ep, 
not only because Z^ is the letter of highest frequency, hut also because it 
combines with several other high-frequency letters, such as Dq , F^, G^, etc. 
The nine letters of next highest frequency ares 

23 22 19 19 16 . 15 1-1 lO 10 

DTFGVHYSI 

Let the combinations these letters form i/ith Z^ be indicated in the follow- 
ing manner. 

Ho. of times 
Zjj occurs^ as 
prefix 

Cipher Letteri 

llo. of times 
Zj. occurs as 
suffix 

Consider D^. It occurs 23 times in the message and 18 of those times it is 
combined with Z^, 9 times in the form (« E0p) , and 9 times in the form 

OgZg (=0Ep) . It is clear that must be a consonant. In the same way, 
consider Tg , which shows 9 combinations mth Zg , 4 in the form Z^T^ (= S0p) 
and 5 in the form T^.Zq (» 0Ep) . The letter Tq appears to represent a con- 
sonant, as do also tho letters , G^, and Yq. On the other hand, consider 
Vq , occurring in ail 16 times but never in combination with it appears 
to represent a vowel, as does also the letters , Sg, and Iq. So far, 
then, the following classification would seem logical: 

Vov/els Consonants 

Zc(* V’ Sc. Ic -Dc G^, Yq 

29. Further analysis of the letters representing vowels and consonants, 
a. Op is usually the vo’-el of second highest frequency. Is it possible to 
determine which of the letters V, H, S, I^. is the cipher equivalent of Opi 
Let reference bo made again to Table 11 in Appendix 1, where it is seen that 
the 10 most frequently occurring diphthongs are. 

Uiphthong - 10 OU SA SI AI IE AU EO AY U3 

Frequency - 406 365 345 273 172 131 128 121 120 114 



- D(23) T(22) F(19) G(l9) V(16) H(15) Y(14) S(10) I(10) 



REF J5^: A64644 

If V, rij S, are really the cipher equivalents of A, I, 0, Up (not re,- 
spectively ) , perhaps it is possible to determine v/hich is which bv examin- 
ing the combinations they ..lake among themselves and with (« E^) . Let 
the combinations of V, 6, I, and Z that occur in the message be listed. 
There are only the following; 





ZZc(= 


) - 4 
- 2 


HI 


- 1 


w* 


VH 


SV 


- 1 




HH 


- 1 


IS 


- 1 



Note the doublet if is a vov/el, then the chances are excelleht 

that Hg = 0 , because the doublets -aAp, Hp» practically non-ex- 

istent, whereas the double vowel combination, OOp, is of next highest 
frequency to the double vowel combination, If = Op, then Vq must 

be Ip because the digraph WIq occurring two tines in the nessage could 
hardly be AOp, or UOp, whereas the diphthong lUp is the one of high fre- 
quency in jiJnglish. So far then, the tentative (because so far unverified) 

results of the analysis are as follows. 

2c = Ep He = Op ^0 » h 

This leaves only two letters, I^. eind S^. , classified as vowels, to be sep- 
arated into Ap and Up. Note the digraphs; 

HIc = 09 
SVe = eit) 

ISc = e©*p 

Only two alternatives are open. 

(1) Jlither Ij. = Ap and Sg = Up, 

(2) Or Ig * Up and Sg = Ap. 

If the first alternative is selected, then 

HIg s OAp 
SVg s UIg 

is.° . AO^ 

If the second alternative is selected, then 

filg = OUp 
SVe - Alp 
ISc = UAp 

The eye finds it difficult to choose between these alternatives; but sup- 
pose the frequency values of the plain-text diphthongs as given in Table 11 
of Appendix 1 are added for each of these alternatives, giving the follow- 
ings 



ID:A64644 



SVc 



Oiip, frequency value = 72 
UIp, frequency value » 46 
AUp, frequency value = 128 

Total 246 




OU , frequency value ®355 
UIp, frequency value =172 
AUp, frequency value = 48 

Total 535 



Mathematically, the second alternative is almost twice as probable as the 
first. Let it be assumed to be correct and the following (still tentative) 
values are nov/ at hand.’ 




b. Attention is now directed to the letters classified as consonants, 
ilow far is it possible to deteraine their values? The letter, Dg, from 
considerations of frequency alone, would seem to be T , but its frequency, 
23, is not considerably greater than that for Tg. It^is not much greater 
than that for or Gg, with a frequency of 19 each. But perhaps it is 
possible to determine not the value of one letter alone but of two letters 
at one stroke. To do this one may make use of a tetragraph of considerable 
importance in Jlnglish, viz., TIOKg, For if the analysis pertaining to the 
vowels is correct, and if VHg =■ lOp, then an examination of the letters 
immediately before and after the digraph VH in the cipher text might dis- 
close both Tp and Np. Reference to the text gives the following: 

GVHTo FVHTg 

8I0«p QIOSp 

The letter T^, follovvs VHc in both cases, indicates very probably that Tg = 
IIp 5 but as to whether Gg or Fg equals Tp cannot be decided. However, two 
conclusions are clear; first, the letter Dg is neither Tp nor Np, from 
which it follows that it must be either Rp or Sp; second, the letters Gg 
and Fg must be either Tp and Sp, respectivaly, or S and Tp respectively, 
because the only tetragraphs usually found (in English) containing the 
diphthong lOp as central letters are blOiIp and TIOIIp. This in turn means 
that as regards Ug, the latter cannot be either Rp or 5p; it must be Kp, 
a conclusion which is corroborated by the fact that ZDg ( = ERp)and 
(= occur 9 times each. Thus far, then, the identifications, v/hen in- 

serted in an enciphering alphabet, are as follows. 

Plain : ABCUEFGHIJKLtIUOP'iRSTUV.ifXYZ 

Cipher: S Z V TH JGFI 

F G 



REF_ JPj A6 4644 



30 o Substituting deduced values in the cryptogram. - a. Thus far 
the analysis has been almost purely hypothetical, for as yet not a single 
one of the values deduced from the foregoing analysis has been tried out 
in the cryptogram. It is high time that this be done, because the final 
test of the validity of the hypotheses, assumptions and identifications 
made in any cryptographic study is, after all, only this; do these 
hypotheoes, assumptions and identifications ultimately yield verifiable, 
intelligible, plain-text when consistently applied to the cipher text? 

b. At the present stage in the process, since there are at hand 

the assumed values of but 9 out of the 25 letters that appear, it is ob- 
vious that a continuous "reading" of the cryptogram can certainly not be 
expected from a mere insertion of the values of the 9 letters. However, 
the substitution of these values should do tv/o things: first, it should 

immediately disclose the fragments, outlines, or "skeletons" of "good" 
v/ords in the text; and second, it should disclose no places in the text 
v'here "impossible" sequences of letters are established. By the first is 
meant that the partially deciphered text should show the outlines or 
skeletons of v/ords such as may be expected to be found in the conununica- 
tion; this will become quite clear in the next subparagraph. By the 
second is meant that sequences, such as "AOOjSN" or "THRS3iI0" or the like, 
obviously not possible or extremely unusual in normal English text, must 
not result from the substitution of the tentative identifications result- 
ing from the analysis. The appearance of several such extremely unusual 
or impossible sequences at once signifies that one or more of the assumed 
values is incorrect. 

c. Here are the results of substituting the nine values which have 
been deduced by the reasoning based on a classification of the high-fre- 
quency letters into vowels and consonants and the study of the members of 
the tv/o groups; 



REF ID:A64644 




A 



12 3 

10 19 23 
S F D 
A T R 



t3 



19 16 15 

B G V H 

S I 0 

T 

8 10 22 

0 AIT 

N 



D 



23 19 
D F 
R T 
S 



8 

X 






22 15 5 

T H L 
H 0 



F 



22 35 23 
T Z D 
N B R 



G 



23 22 15 
DTK 
a N 0 



H 



14 23 35 

y D Z 

R E 



35 19 35 
J Z F Z 

B T E 
S 

3 19 15 
K 3 G H 

S 0 
T 

d. Ho 
long words, 
tlons: 



- 62 - 



4 


5 


6 


7 


8 


9 


10 


11 


12 


13 


14 


15 


16 


17 


18 


19 


20 


21 


22 


23 


24 


25 


35 


19 


10 


3 


19 


15 


5 


5 


35 


19 


19 


35 


23 


14 


10 


5 


19 


15 


4 


35 


23 


10 


Z 


F 


I 


0 


G 


H 


L 


P 


Z 


F 


G 


Z 


D 


Y 


S 


P 


F 


H 


B 


Z 


D 


S 


E 


T 






S 


0 






3 


T 


S 


B 


R 




.A 




T 


0 




B 


R 


A 




S 






T 










S 


T 












S 












22 


19 


5 


5 


5 


16 


23 


19 


19 


14 


16 


3 


16 


19 


16 


15 


22 


19 


8 


23 


35 


35 


T 


F 


U 


P 


L 


V 


D 


F 


G 


Y 


V 


J 


V 


F 


V 


H 


T 


G 


A 


D 


Z 


Z 


N 


T 








I 


R 


T 


S 




I 




I 


T 


I 


0 


N 


S 




R 


B 


B 




S 












S 


T 










S 








T 










14 


23 


35 


14 


19 


35 


3 


35 


22 


19 


5 


22 


16 


22 


35 


4 


23 


16 


19 


15 


22 


35 


Y 


D 


Z 


Y 


F 


Z 


J 


Z 


T 


G 


P 


T 


V 


T 


Z 


B 


D 


V 


F 


H 


T 


Z 




R 


B 




T 


B 




B 


N 


S 




N 


I 


H 


E 




R 


I 


T 


0 


N 


B 










S 










T 


















S 








10 


4 


19 


10 


23 


35 


14 


16 


22 


8 


3 


10 


14 


16 


22 


3 


19 


16 


2 


19 


35 


35 


S 


B 


G 


I 


D 


Z 


Y 


V 


T 


X 


0 


I 


Y 


V 


T 


3 


F 


V 


H 


G 


Z 


Z 


A 




S 




R 


B 




I 


N 










I 


W 




T 


I 




S 


B 


B 






T 




























S 






T 






5 


16 


8 


35 


23 


19 


2 


15 


22 


35 


8 


10 


22 


14 


23 


35 


14 


4 


23 


16 


19 


15 


L 


V 


X 


Z 


D 


F 


M 


H 


T 


Z 


A 


I 


T 


Y 


B 


Z 


y 


B 


D 


V 


F 


H 




I 




B 


R 


T 




0 


H 


B 






N 




R 


B 






R 


I 


T 


0 












S 






























S 




19 


2 


35 


23 


35 


35 


3 


10 


8 


10 


10 


19 


35 


14 


19 


8 


16 


19 


10 


5 


19 


35 


F 


K 


Z 


D 


Z 


Z 


J 


s 


X 


I 


S 


G 


Z 


Y 


G 


A 


V 


F 


S 


L 


G 


Z 


T 




B 


R 


E 


B 




A 






A 


S 


E 




S 




I 


T 


A 




S 


B 


5 






















T 






T 






S 






T 




15 


22 


1 


23 


35 


2 


10 


16 


22 


14 


35 


23 


3 


35 


19 


19 


15 


22 


35 


8 


10 


22 


H 


T 


C 


J 


Z 


R 


S 


V 


T 


Y 


Z 


D 


0 


Z 


F 


F 


H 


T 


Z 


A 


I 


T 


0 


N 




R 


B 




A 


I 


H 




B 


R 




B 


T 


T 


0 


II 


E 






N 






























5 


S 














14 


19 


8 


16 


23 


19 


35 


35 


22 


2 


15 


10 


22 


14 


35 


14 


10 


23 


35 


19 


15 


5 


Y 


G 


A 


V 


D 


G 


Z 


Z 


T 


K 


H 


I 


T 


y 


Z 


Y 


S 


D 


Z 


G 


H 


U 




S 




I 


R 


S 


B 


B 


N 




0 




N 




B 




A 


R 


E 


S 


0 






T 








T 




























T 






22 


19 


5 


5 


19 


23 


10 


8 


1 


24 


15 


8 


8 


10 


2 


5 


35 


23 


19 


5 


10 


23 


T 


G 


U 


P 


G 


D 


I 


X 


W 


G 


H 


X 


A 


s 


R 


U 


Z 


D 


F 


U 


I 


D 


N 


S 






S 


R 








S 


0 






A 






B 


R 


T 






R 




T 






T 










T 


















S 








22 


16 


3 


8 


19 


8 


8 
































T 


V 


3 


A 


G 


X 


X 

































N I S 

T 

impossible sequences are b -ought to light, and, moreover, several 
nearly complete, stand out in the text. Note the following por- 








REF ID:A64644 



A21 B5 

HBZDSCtVHTF 
(1) 0 Z ’l A 3 I 0 J T 

T S 

D2 

DVFHTZDF 
R I T 0 N i3 R T 

■ 3 s' 

F22 G5 

S LGZDTHHT 
(3) A S 3 R ‘ N 0 0 N 

T 

The words are obviously OP3 RaTIONSj NINF PRISOIORS j and AFTCRMOON. The 
value Gq is clearly Tpj that of F^, is Spj and the following additional 

values are certain; 



CIS 

T V T Z B 

(2) II I K E 




31. Completing the solution. - a. Each tine an additional value is 
obtained, substitution is at once made throughout the cryptogram. This 
leads to the determination of further values, in an ever-widening circle, 
until all the identifications are firmly and finally established, and the 
message is completely solved. In this case the decipherment is as follows; 



B 



D 



F 



H 

J 

K 



1 


2 


-_3 


4 


5 


6_ 


7 


. 8 


9 


10 


11 


12 


13 


14 


15 


16 


17 


18 


19 


20 i21 


22 


23 


24 25 


s' 


F 


D 


Z 


F 


r* 


0 


’ G 


H 


l“ 


p 


Z 


F 


G 


Z 


d" 


Y 


S 


P 


F 


H 


B 


Z 


D 


s 


A 


S 


R 


E 


S 


u 


L 


T 


0 


F 


Y 


3 


S 


T 


E 


R 


D 


A 


Y 


S 


0 


P 


E 


R 


A 


G 


V 


H 


T 


F 


u 


P 


L 


V 


D 


F 


G 


Y 


V 


J 


V 


F 


V 


R 


T 


G 


A 


D 


Z 


Z 


T 


I 


0 


N 


S 


3 


Y 


F 


I 


R 


S 


T 


D 


I 


V 


, I 


S 


I 


0 


N 


T 


H 


R 


3 


E 


A 


I 


T 


Y 


J 


z 


Y 


F 


Z 


J 


Z 


T 


G 


P 


T 


V 


T 


z 


B 


D 


V 


F 


H 


T 


Z 


H 


u 


N 


D 


R 


3 


I) 


S 


3 


V 


s 


N 


T 


Y 


N 


I 


il 


E 


•P 


■ R 


I 


• S 


0 


N 


E 


D 


F 


X 


S 


B 


G 


I 


D 


Z 


Y 


V 


T 


X 


0 


I 


Y 


V 


T 


E 


F 


V 


M 


G 


Z 


Z 


R 


S 


C 


A 


P 


T 


U 


R 


3 


3 


I 


K 


c 


L 


U 


D 


I 


N 


G 


S 


I 


X 


T 


E 


E 


T 


H 


L 


L 


V 


X 


Z 


D 


F 


la 


H 


T 


z 


A 


I 


T 


Y 


D 


Z 


Y 


B 


D 


V 


F 


H 


N 


0 


F 


F 


I 


C 


3 


R 


S 


X 


0 


N 


3 


H 


u 


N 


D 


R 


3 


3 


P 


R 


I 


S 


0 


T 


,Z 


D 


F 


K 


Z 


D 


Z 


Z 


J 


• S 


X 


I 


S 


G 


Z 


Y 


G 


A 


V 


F 


S 


L 


G 


Z 


N 


E 


R 


S 




E 


R 


E 


E 


V 


A 


C 


U 


A 


T 


E 


D 


T 


K 


I 


S 


A 


F 


T 


E 


D 


T ' 


H 


H 


T 


C 


D 


Z 


R 


5 


V 


T 


Y 


Z 


D 


0 


Z 


F 


F 


H 


T 


Z 


A 


I 


T 


R 


N 


0 


0 


K 


Q 


R 


I 


lI 


A 

t 


I 


N 


D 


3 


R 


L 


E 


S 


S 


0 


11 


E 


H 


U 


N 


Y. 


D- 


Z 


Y 


G 


A . 


V 


D 


G 


z 


z 


T 


K 


H 


I 


T 


Y 


Z 


Y 


S 


D 


Z 


G 


H 


U 


,D 


R 


E 


D 


T 


H 


I 


R 


T 


3 


E 


N 


VI 


0 


U 


H 


D 


3 


0 


A 


R 


E 


T 


0 


B 


Z- 


F 


Z 


T 


G 


-U 


P 


G 


D 


I 


X 


If 


G 


H 


X 


A 


S 


R 


U 


Z 


D 


F 


U 


I 


D 


S 


S 


E 


N 


T' 


3 


Y 


T 


R 


U 


G 


K 


T 


0 


c 


H 


A 


1 


B 




R 


S 


B 


U 


R 


S 


G 


H 


T 


V 


E 


A 


G 


X 


X 
































G 


T 


0 


N 


I 


■G 


K 


T 


X 


X 

































REF ID:A64644 



- 64 

Messages AS RilBUjuT OF fjSSTSRJAYS OPE.'UTIONS BY Fli^T DIVISION THRiSE HUN- 
DRED SEVENTY HIliE rlESONBRS CAPTURED INCLUJIUO SIXTEEN OFFICERS ONE HUN- 
DRED PRISONERS \rERE EVACUATED THIS AFTERNOON REIIAIHDER LESS 01® HUNDRED 
THIRTEEN V/OUNDED ARE TO BE SENT BY TRUCK TO GHAiilBERSBURG TONIGHT 

b. The solution should, as a rule, not be considered complete until 
an attempt has been made to discover all the elements underlying the gen- 
eral system and the specific key to a message. In this case, there is no 
need to delve further into the general system, for it is merely one of 
monoalphabet ic substitution with a mixed cipher alphabet. It is necessary 
or advisable, however, to reconstruct the cipher alphabet because this may 
give clues that later may becomia valuable. 

c, . Cipher alphabets should, as a rule, be reconstructed by the 
cryptanalyst in the form of enciphering alphabets because they will then 
be in the form in v/hich the encipherer used them. This is important for 
two reasons. First, if the sequence in the cipher component gives evidence 
of system in its construction or if it yields clues pointing toward its 
derivation from a keyword or a key-phrase, this may often corroborate the 
identifications already made and may lead directly to additional identifi- 
cations. A word or two of explanation is advisable here. For example, 
refer to the skeletonized enciphering alphabet given at the end of par. 29b: 

Plain : ABCDEFGHIJKLHNOPQRSTUV 'XYZ 

■ Cipher: S 2 V TH DGFI 

F G 

Suppose the cryptanalyst, looking at the sequence DGFI or DFGI in the cipher 
component, suspects the presence of a kejrword-mixed alphabet. Then DFGI 
is certainly a more plausible sequence than DGFI. Again, noting the se- 
quence 5. , ,Z. . .V. . . ,TH, ,D, he might have an idea that the keyword begins 
after the Z and that the TH is followed by AB or BC. This would mean that 
either P, Qp « A, 3^. or B, C^. Assuming that P, Qp = A, Bg, he refers to 

the frequency distribution and finds that the assumptions Pp = Ag and Qp * 

Bq are not goodj on the other* hand, assuming that P, Qp » B, C^, the fre- 
quency distribution gives excellent corroboration, A trial of these values 
would materially hasten solution because it is often the case in crypt- 
analysis that if the value of a .very low-frequency letter can be surely 
established it will yield clues to other values very quickly. Thus, if Q 
is definitely identified it almost invariably will identify Up, and will 
give clues to the letter following the U_i since it must be a vowel. In 
the case under discussion the identification PQp = BCg would have turned 
out to be correct. For the foregoing reason an attempt should always be 
made in the early stages of the analysis to determine, if possible, the 
basis of construction or derivation of the cipher alphabet; as a rule this 
can be done only by means of the enciphering alphabet, and not the decipher- 
ing alphabet. For example, the skeletonized deciphering alphabet correspond- 
ing to the enciphering alphabet directly above is as follows: 



Cipher- 
i-^ain - 



REF ID : A64644 

-65- 

ABGDSFGHIJPCL.iNOPQrtSTUVVXYZ 
RTSOU AN I Z 

S T 

Here no evidences of a keyvjord -mixed alx^habet are seen at alio Hov/ever, 
if the enciphering alphabet has been examined and shows no evidences of 
systematic constructions the deciphering alphabet should then be examined 
with this in view, because occasionally it is the deciphering alphabet 
which shows the presence of a key or keying element , or which has been 
systematically derived from a v;ord or phrase o The second reason why it 
is important to try to discover the basis of construction or derivation 
of the cipher alphabet is that it affords clues to the general type of 
keywords or keying elements employed by the enemy. This is a psychological 
factor, of course, and may be of assistance in subsequent studies of his 
traffic. It merely gives a clue to the general type of thinking indulged 
in by certain of his cryptographers. 

d. In the case of the foregoing solution, the complete enciphering 
alphabet is found to be as follows; 

Plain ; A 3 C J I F C H I J L -i II 0 P 1 S T U V 7 X Y Z 

Cipher- SUXYZL^AVHIJORTHBCDFGIIJXhP- 

Obviously, the letter Q, which is the only letter not appearing in the 
cryptogram, should follov/ P in the cipher component. Note now that the 
latter is based upon the keywortl lulAVjlN ORTH, and that this particular 
cipher alphabet has been composed by shifting the mixed sequence based 
upon this keyword six intervals to the right so that the key for the 
message is A = S^., Note also that the deciphering alphabet fails to give 
any evidence^of keyword construction based upon the word LEAVEN’.TORTH . 

Cipher- ABCO3 FGHIJKLmN0P;rSTUV/XYZ 

Plain ; H P Q R G S T 0 U V I F X J L Y Z II A M B I K C D 3 

e. If neither the enciphering or the deciphering alphabet exhibits 
characteristics which give indication of derivation from a keyword by some 
form of mixing or disarrangenent, the latter is nevertheless not finally 
excluded as a possibility. The student is referred to pars. 46 and 47 of 
Special Text i}o. 165, Elementary i.ilitary Cryptography, wherein will be 
found methods for dei'iving mixed alphabets by transposition methods ap- 
plied to keyword -mixed alphabets. For the reconstruction of such mixed 
alphabets the cryptanalyst must use ingenuity and a knowledge of the more 
common methods of suppressing the appearance of heyvords in the mixed 
alphabet s . 

32. General notes on the foregoing solution. - a. The example 
solved above is admittedly a more or less artificial illustration of the 
steps in analysis, made so in order to demonstrate general principles. 

It was easy to solve because the frequencies of the various cipher let- 
ters CO 'responded quite \'ell with the normal or expected frecuencies. 
However, all cryptograms of the same monoalphabetical nature can be solved 
along the same general lines, after more or less experimentation, depend- 
ing upon the longth of the cryptogram, the skill, and the experience of 
the cryptanalyst . 



RBF -ID : A64644 



b. It is no cause for discouragement if the student's initial at- 
tempts to solve a cryptogram of this type require much raore time and ef- 
fort than were apparently required in solving the foregoing purely il- 
lustrative example. It is indeed rarely the case that every assumption 
made by the cryptanalyst proves in the end to have been correct; more 
often is it the case that the majority of his initial assumptions are in- 
correct, and that he loses much time in casting out the erroneous ones. 

The speed and facility with which this elimination process is conducted 
is in many cases all that distinguishes the expert from the novice. 

c. . Nor will the student always find that the initial classification 
into vowels and consonants can be accomplished as easily and quickly as 
v/as apparently the case in the illustrative example. The principles in- 
dicated are very general in their nature and applicability, and there are, 
in addition, some other principles that may be brought to bear in case of 
difficulty. Of these, perhaps the most useful are the follov/ing. 

(1) In nomal English it is unusual to find two or 
three consonants in succession, each of high frequency. 

If in a cryptogram a succession of three or four let- 
ters of high-frequency appear in succession, it is 
practically certain that at least one of these repre- 
sents a vowel. ^ 



(2) buccessions of three vowels are rather unusual 
in English. 2 Practically the only time this happens is 
when a word ends in tv/o vowels and the next word begins 
with a vowel. 3 



(3) ."hen two letters already classified as vowel- 
equivalents are separated by a sequence of six or raore 
letters, it is either the case that one of the supposed 
vowel-equivalents is incorrect, or else that one or raore 
of the intemediate letters is a vowel-equivalent.^ 

^ Sequences of seven consonants are not impossible, however, as in 
STRE NGTH THROUGH. 

2 Note that the -;ord RnUICED, past tense of the verb RADIO, is coming into 
usage. I 

^ A sequence of five vowels is not impossible, however, as in YOU AUT HORIZE. 



4 Some cryptanalysts place a good deal of emphasis upon this principle as a 
method of locating the remaining vowels after the first two or three have 
been located. They recommend that the latter be underlined throughout the 
text and then all sequences of five or raore letters showing no underlines 
be studied attentively. Certain letters which occur in several such se- 
quences are sure to be vov/els. An arithmetical aid in the study is as fol- 
lows: Take a letter thought to be a good possibility as the cipher equiva- 

lent of a vowel (hereafter termed a possible vowel-ejui valent) and find the 
length of each interval from the possible vovrel-equivalent to the next know n 
(fairly surely determined) vowel-equivalent, uultiply the interval by the 
number of times this interval is found. Add the products and divide by the 
total number of intervals considered. This vfill give the mean interval for 
that possible vowel-equivalent. Jo the same for all the other possible vov/el- 
equi valent s. The one for which the moan is the greatest is most probably a 
vowel-equivalent. Underline this letter throughout the text and repeat the 
process for locating additional vov/el-equivalents , if any remain to be located. 



REF ID:A64644 



- 67 - 

(4) Reference to Table 7B of Appendix 1 discloses 
the follojving. 

Distribution of 1st 18 digraphs forming 25/o of English 
text 



No. of consonant-consonant digraphs - 4 
No. of consonanti-vojyel digraphs - 6 
No. of vov/el-cpnsonant dig'^aphs - 8 
No. of vov;el- vowel digraphs - 0 



Distribution of 1st 53 digraphs forming 50/ of iinglish 
text- 



No. .of consonant -consonant digraphs - 8 

.No. of consonant-vowel digraphs . - 23 

No. of vowel-consonant digraphs ' - 18 

No. of vowel- vowel digraphs - 4 



The latter tabulation shows that of the first 53 di- 
graphs \/hich form 50/ of JJnglish text, 41 of bhem, 
that is, over 75/, are combinations of a vowel v/ith a 
consonant. In short, in normal English the voi/els and 
the high-frequency consonants are in the long run dis- , 
tributed fairly evenly and regularly throughout the 
text . 



(5) As a rule, repetitions of trigraphs in the 
cipher text are composed of high-frequency letters 
forming high-frequency combinations. The latter prac- 
tically always contain at least one vowel; in fact, if 
reference is made to Table 13 of Appendix 1, it will be 
noted that 36. of the 56 trigraphs having a frequency 
of 100 or raopre contain one vov;el, 17 of them contain 
two vov/els , and only three of them contain no vov/el. 

In the case of tetragraph repetitions, Table 14 of Ap- 
pendix 1 shows that no iatra^graph listed therein fails 
to contain at least one vowel, 28 of them contain one 
vowel, 25 contain two vov/els, and 2 contain three 
vowels. 

(6) ■^uite frequently ’^hen two' kno\'n vowel-equiva- 
lents are separated by six or more letters none of which 
seens to be ’of sufficiently high frequency to repre- 
sent one of the .vowels A E I 0, the chances are good 
that the cipher-equivalent of the vowel U or Y is pres- 
ent. (See' Fo'ofnote No. 4, page 66) 

(7) The letter D is invariably followed by U; the 
letters J and V are invariably followed 'by a vowel. 



_ID : A64644 



d. In the foregoing example the amount of experimentation or "cutting 
and fitting" was practically nil. (This is not true of real cases as a 
rule.) jhere such experimentation is necessary, the underscoring of all 
repetitions of several letters is very essential, as it calls attention to 
peculiarities of structure that often yield clues. 

e. After a few basic assumptions of values have been made, if short 
words or skeletons of words do not become manifest, it is necessary to make 
further assumptions for unidentified letters. This is accomplished most 
pften by assuming a word.^ Now there are two places in every message which 
lend themselves more readily to successful attack by the assumption of vrords 
than do any other places, the very beginning and the very end of the message. 
The reason is quite obvious, for although words may begin or end with almost 
any letter of the alphabet , they usually begin and end with but a few very 
common digraphs and trigraphs. In this connection reference should be mside 
to Tables 15 and 16 of Appendix 1. Very often the association of letters in 
peculiar combinations will enable the student to note where one word ends 

and the next begins. For example, suppose E, H, S and T have been definitely 
identified, and a sequence like the following is found in a cryptogram. 

EWTSNE 

Obviously the break between two words should fall either after the S of 
il N T S or after the T of E N T, so that two possibilities are offered v 
. . .ENTS/NE. . .,or. . .^NT/SNE. . . . Since in English 
there are very few words with the initial trigraph S N E, it is most likely 
that the proper division is . . . E W T S / N E . . . • Obviously, when 
several v/ord divisions have been found, the solution is rendered more easy 
by virtue of the greater ease with v/hich assumptions of additional new 
values may be made. 

33. The "probable-word" method? its value and applicability. - a. 

In practically all cryptanalytic studies, short-cuts can often be made by 
assuming the presence of certain words in the message under study. Some 
writers attach so much value to this kind of an "attack from the rear" that 
they practically elevate it to the position of a method and call it the 
"intuitive .method" or the "probable -word method". It is, of course, merely 
a refinement of what in every-day language is called "assuning" or "guessing" 
a word in the message. The value of making a "good guess" can hardly be 
overestimated, and the cryptanalyst should never feel that he is accomplish- 
ing a solution by an illegitimate subterfuge when he has made a fortunate 
guess leading to solution, a correct assumption as to plain text will often 
save hours or days of labor, and sometimes there is no alternative but to 
try to "guess" a word, for occasionally a system is encountered the solu- 
tion of which is absolutely dependent upon this artifice. 

^ This process does not involve anything more mysterious than ordinary, 
logical reasoning? there is nothing of the subnormal or supernormal about 
it. If cryptanalytic success seems to require processes akin to those of 
medieval magic, if "hocus-pocus" is much to the fore, the student should 
begin to look for items that the claimant of such success has carefully 
hidden from view, for the mystification of the uninitiated. (See Par. 33 
in this connection.) 



REF ID:A64644 



- 59 - 



bo The expression "'jooa jjuess” is used advisedly. For it is "good!* 
in tv/o respects. First, the cryptanalyst aust use care in making his as- 
sumptions as to plain-text Tords. In this he must be guided by extraneous 
circumstances leading to the assumption of probable words - not just any 
words that come to his mind. Therefore he must use his imagination but 
he must nevertheless carefully control it by the exercise of Fcopd judg- 
ment. Second, only if the "guess" is correct and leads to solution, or 
at least puts him on the road to solution, is it a good guess* - But, while 
realizing the usefulness and the time and labor-saving features of a solu- 
tion by assuming a probable word, the cryptanalyst should exercise discre- 
tion in regard to how long ha may continue in his efforts with this method, 
sometimes he may actually vjaste time by adhering to the method too long, 
if straightforv/ard , methodical analysis '.'ill yield results more quickly. 



£. Obviously, the '* probable-word" method has much more applicability 
when v/orking upon material the general nature of v/hich is kno\m, than when 
'jvorking upon more or less isolated communications exchanged between cor- 
respondents concerning whom or whose activities nothing is known. For in 
the latter case there is little or nothing that the imagination can seize 
upon as a background or basis for the assumptions.^ 



d. Very frequently, the choice of probable words is aided or limited 
by the number and positions of repeated letters. These repetitions may be 
patent . that is, externally visible in the cryptographic text as it orig- 
inally stands, or they may be l at ent . that is, externally invisible but 
susceptible of being made patent as a result of the analysis. For example, 
in a mo noalphabet ic substitution cipher, such as that discussed in the pre- 
ceding paragraph, the repeated letters’ are directly exhibited in the crypto 
gran; later the student will encounter many cases in which the repetitions 
are latent, but are made patent by the analytical process. ihen the repeti 
tions are patent, then the pattern or fonjula to which the repeated letters 
conform is of direct use in assuming plain-text words; and when the- text 
i’s in word-lengths 3 the pattern is obviously of oven greater assistance. 
Suppose the cryptanalyst is dealing v/ith military text, in v/hich ’case he 
nay expect such v/orde'as JIVISlilN, BATTALiIOlI, etc., to be present in the 
text. The positions of the repeated letter I in DIVlSIONi of the revers- 
ible digraph AT, TA in BATTaLION, and so on, constitute for the experienced 
cryptanalyst, tell-tale indications of the p''esence of these \'ords, even 
■■/hen the text is not divided up into its original v/oni lengths. 

^ Greneral Givierge in his ' Pours de Crypt ographie (p. I2l) says "However, 
expert cryptanalysts often employ such details as are cited above p.n con- 
nection with assu.jing the presence of 'probable v/ords'l, and the experience 
of the years 1914 to 1913, to cite only those, prove that in practice one 
often has at his disposal elements of -this nature, permitting assumptions 
much' more audacious than those v/hich served for the analysis of the last 
exaraple. The reader -would therefore be v/rong in imagining that such for- 
tuitous elements are encountered only in cryptographic v/orks v/here the 
author deciphers a document that he himself enciphered. Cryptographic 
correspondence, if it is extensive, and if sufficiently numerous v/orking 
data are at hand, often furnishes elements so complete that an author would 
not dare use all of them in solving a p oblem for fear of being accused of 
obvious exaggeration." 



ID : A64644 



e. The important aid that a study of word patterns can afford in 
cryptanalysis warrants the use of definite terminology ana the establish- 
ment of certain data having a bearing thereon. The phenomenon herein 
under discussion, namely, that many vrords are of such construction as re- 
gards the number and positions of repeated letters as to make them readily 
identifiable, will be termed idi o mornhi sm (from the Greek "idios" - one's 
own, individual, peculiar + "morpl-o" - form). '.;ords which show this 
phenomena will be termed i dicmorplii c. It wo.ll be useful to deal with the 
idioraorphisms symbolically and systematically as described below. 

f. '/hen dealing with cryptograms in which the word lengths are de- 
termined or specifically shown, it is convenient to indicate their lengths 
and their repeated letters in somo easily rec*ognized manner or by formulas. 
This is exemplified, in the case of the word /D'lVISION, by the formula 
ABGBDBiSF; in the case of the v/ord BATTiiLIGi^, by the formula ABCCBBE^G If 
the cryptanalyst , during the course of his studies, makes note of striking 
formulas he has encountered, with the words which fit them, after some time 
he will have assembled a quite valuable body of data. And after more or 
less complete lists of such formulas have been established in some systematic 
arrangement, a rapid comparison of the idiomorphs in a specific cryptogram 
with those in his lists \yill be feasible aiid Jill often lead to the assump- 
tion of the correct word. Such lists can be arranged according to word 
length, as shown herewithi 



3/aba : 


DID, 3VB, EYE 


abb i 


AJD, ALL, ILL, OFF, etc. 


4/abac ; 


ARAB, AREA, A /AY, etc. 


abca : 


B0L3, DEAD, etc. 


abbc 1 


• • « 


abcb : 


• • • 


etc. 


etc. 



g. /hen dealing with cryptographic text in which the lengths, of the 
words are not indicated or otherwise determinable, lists of the foregoing 
nature are not so useful as lists in which the words (or parts of words) 
are arranged according to the intervals between identical letters, in the 
following manner; 

1 Interval , 2 Intervals 3 Intervals Repeated digraphs 

-DiD- AbbAcy AbeyAnce COCOa 

-EvE- ArAbiA hAbitAble dBRBR 

-EyE- AbiAtive lAborAtory ICICle 

division AboArd AbreAst ININg 

revision -AciA- AbroAd bAGgAGe 

etc. etc. etc. etc. 

In Appendix 2 will be found some useful lists of words arranged in this 
manner. 

34. Solution of additional cryptograms produced by the same cipher 
component. - a. To return, after a rather long digression, to the crypto- 
gram solved in pars. 28 - 31, once the cipher component of a cipher alphabet 



REF ID:A64644 

- 71 - 



has heen reconstruct 3d , subsequent 'aessages ■■vhich have been enciphered by 
means of the same cipher connonenb may be solved very rendily, and ’vithout 
recourse to the principles of frequency, or application of the "probable- 
word ■' method. It has been se-.n that the illustrative cryptogram treated 
in paragraphs 24 - 31 i/as enciphered by juxtaposing the cipher component 
against the normal sequence so that Ap = It is obvious that the cipher 

component may be set a ;ainst the plain component at any one of 26 differ- 
ent points of coincidence, each yielding a different cipher alphabet. 

After a cipher component has been reconstructed, however, it becomes a 
knovm sequence, and the method of converting the cipher letters into their 
plain-component equivalents and then completing the plain-component sequence 
begun by each equivalent can be applied to solve any cryptogram which has 
been enciphered by that cipher component. 

b. An example will serve to make the process quite clear. Suppose 
the following message passing between the same two stations as before was 
intercepted shortly after the first message had been solved- 

I Y 3 ■/ K G jJ N ; 0 F 0 S 3 L F 0 0 H 3 A Z X X 

It is assumed that the same cipher component -.vas used, but v/ith a differ- 
ent key latter. First the initial group or two groups are converted into 
their plain-component equivalents by setting the cipher component against 
the normal sequence at any arbitrary point of coincidence. The initial 
letter of the former may as well be set against A of the latter, with the 
following result. 

Plain - aBCJSFGHIJKLIIUOPQRSTUV’/XYZ 

Cipher. L 3 A V N 7 0 R T H 3 C D F G I J i: li P ^ S U X Y Z 

Cryptogram ; I Y 3 '■/ K C 3 R il 7 ... 

equivalents. rYBFRL3H3F 

The nomal sequence initiated by each of these conversion equivalents is 
now completed, with the results shown in Fig. 15. liote the plain-text 
generatrix, CLOSIfOURS, which manifests itself Ithout further analysis. 

The rest of the message may be read either by continuing the same process, 
or, what is even more simnle, the key letter of the message may now be 
detenained quite readily and the message deciphered by its means. 



-W ID : A64644 



I 


Y 


3 


! 


K 


c 


3 


R 


JL 


N 


p 


y' 


B 


F 


R 


L 


3 


H 


3 


F 


0 


z 


C 


G 


S 


lu 


G 


I 


F 


G 


R 


A 


D 


H 


T 


w 


D 


J 


G 


H 


S 


B 


S 


I 


U 


0 


3 


K 


H 


I 


T 


C 


F 


J 


V 


p 


F 


L 


I 


J 


U 


J 


G 


K 






G 




J 


K 


V 


j 


H 


L 


X 


R 


H 


N 


i: 


L 


'/ 


F 


I 


H 


Y 


s 


I 


0 


L 


i'. 


X 


G 


J 


N 


Z 


T 


J 


P 


k 


N 


Y 


H 


K 


0 


A U 


K 


Q 


N 


0 


Z 


I 


L 


P 


B 


V 


L 


R 


0 


P 


A 


J 


M 




C W 


M 


S 


P 


Q 


3 


K 


il 


R 


D 


X 


H 


T 


Q 


R 


C 


L 


0 


S 


3 


y 


0 


U 


R 


S 


D 


li 


P 


T. 


F 


z 


P 


V 


S 


T 


3 


N 


1 


U 


G 


A 


1 


•I 


T 


U 


F 


0 


R 


V 


H 


B 


R 


X 


U 


V 


G 


P 


S 


\i 


I 


c 


s 


y 


V 


\I 


H 


a 


T 


X 


J 


D 


T 


z 


T r 


X 


I 


R 


U 


Y 


i: 


E 


U 


A 


X 


Y 


J 


S 


V 


Z 


L F 


V 


B 


Y 


Z 


i; 


T 


\f 


A 




G 


M 


c 


Z 


A 


L 


U 


X 


B 


N 


H 


X 


D 


A 


B 


M 


V 


Y 


C 


0 


I 


Y 


3 


B 


G 


N 


/ 


Z 


D 


P 


J 


Z 


F 


G 


D 


0 


X 


A 


3 




K 


A 


n 

\x 


D 


3 



Fig. 15 



c. In order that the student may understand without question just 
\7hat is involved in the latter step, that is, discovering the key letter 
after the first two or three groups have been deciphered by the conver- 
sion-completion process, the foregoing example irLll be used. It vas noted 
that the first cipher group was finally deciphered as follows. 

Cipher. I Y E v/ K 
Plain : CLOSE 

Now set the cipher component against the nomal sequence so that C„ = I^. 
Thus -. 

Plain ; A B C D F G H I J K L fi M 0 P R S T U V /' X f Z 

Ciphers F G I J K u P S U X Y Z L E A V N 0 R T H B C D 

It is seen here that when Cp » I^. then Ap =* F©. This is the key for the 

entire message. The decipherment may be^completed by direct reference to 

the foregoing cipher alphabet. Thuss 

Cipher; IY37K C3RN'/ 0F0S3 LFOOH SAZXX 

Plain : CLOSE YOURS ThTIO IIATT'/ 0PM XX 

Message. GLOSS YOUR STATION ^T T /O HI 



REF ID : A64644 



- 73 - 

The student should make sure that he understands the fundamental 
principles involved in this quick solution, for they are among the most 
important principles in crypt analytics. How useful they are will become 
clear as he progresses into more and more complex cryptanalytic studies'* 

SEGTiOil VII 

POLfLIT I'bili bUBSTITUriuii V/ITH POiIO-E ^UIVjiLEilT CliilEA nLiijlBETS 

Paragraph 

Analysis of polyliteral, monoalphabet ic substitution systems. . . 35 

Historically interesting examples . 36 

35. Analysis of polyliteral, .jonoalphabetic substitution systems. - 

a. oubstitution methods in general may be classified into monoliteral 
and polvliteral systems.^ In the former there is a strict "one-to-one" 
correspondence bet’.'een the length of the units of the plain and those of 
the cipher text; that is, each letter of the plain text is replaced by a 
single character in the cipher text. In the latter this correspondence 
is no longer lp*lc but may be lp.2g, where each letter of the plain text 
is replaced by a combination of two characters in the cipher text; or 
1 -Sg, where a 3-character combination in the cipher text represents a 
single letter of the plain text, and so on. a cipher in which the corre- 
spondence is of the Ip'lg type is termed raonollteral in character; one in 
which it is of the lp<2Q type, biliteral; Ip 3^, triliteral, and so on. 

Those beyond the IpSJ-c type are classed together as polvliteral . 

b. Vi/hen a polyliteral system employs biliteral e ’uivalents , the cipher 
alphabet is said to be bipartite. Such alphabets are composed of a set of 
25 or 26 combinations of a limited number of characters taken in pairs, i^n 
example of such an alphabet is the following* ♦ 

Plain. ABCDSFGHIJKLliNOPlRS,TUV"/X 
Cipher. 'wV '•fri /C JT G HE HH HI HT HT HE I •/ IH II IT IE TH TH TI TT TE EU EH El 

This alphabet is derived from the square shown in Fig. 16. 

( 2 ) 

WHITE 
W 
H 

(1) I 
T 
E 



A 


B 


C 


D 


E 


F 


vj 


H 


I-J 


K 


L 


M 


N 


0 


P 


9 


R 


S 


T 


U 


V 


W 


X 


Y 


Z 



Fig. 16 



c. If a message is enciphered by means of the foregoing bipartite 
alphabet the cryptogram is still monoalphabet ic in character. .*i. frequency 
distribution based upon pairs of letters -'ill obviously have all the 



1 



See Par. 29. Special Text No. 166, Advanced ..'ilitary Cryptography. 



LU 




ID:A64644 



characteristics of a simplej raonoliteral distribution for a lonoalphabetic 
substitution cipher. 

d. Ciphers of this type, as v/ell as of those of the triliteral, tetra- 
literal, ... type are readily detected externally by virtue of the fact that 
the cryptographic text is composed of but a very limited nu<'’.ber of differ- 
ent characters. They are handled in exactly the same manner as are mono- 
literal, raonoalphabetio substitution ciphers. So long as the same character, 
'or combination of characters is alvra.ys used to represent the same plain-text 
letter, and so long as a given letter of the plain text is alv/ays represented 
by the same character or combination of characters, the substitution is 
strictly monoalphabet ic and can be handled in the simple manner described 
under Par. 31 of this text. 

e. Jin interesting example in which the cipher equivalents are penta- 
.literal groups and yet the resulting cipher is strictly monoalphabetic in 
character is found in the cipher system invented by Sir Francis Bacon over 
300 years ago. Oespite its antiquity the system possesses certain features 
of merit which are well worth noting. Jacon^ proposed the follov/ing cipher 
alphabet, composed of permutations of tv/o elements taken five at a timei 



A 


Ml 


aaaaa 


G 


= 


aabba 


N 


= 


abbaa 


T 


'Z 


baaba 


B 


= 


aaaab 


H 


=: 


aabbb 


0 


= 


abbab 


U-V 


a 


baabb 


C 


= 


aaaba 


I-J 


= 


abaaa 


F 


— 


abbba 


V/ 


tft 


babaa 


D 


r 


aaabb 


K 


ST 


abaab 


0 


EX 


abbbb 


X 


a 


babab 


E 


= 


aabaa 


L 


* 


ababa 


R 


a 


baaaa 


Y 


z 


babba 


F 


s 


aabab 


LI 




ababb 


8 


a 


baaab 


Z 


a 


babbb 



If this ware all there were to Bacon’s invention it would be hardly worth 
bringing to attention. But what he pointed out, with great clarity and 
simple examples, was how such an alphabet might be used to convey a secret 
message by enfolding it in an innocent, external message which might easily 
evade the stricteslj kind of censorship. As a very crude example, suppose 
that a message is written in capital and lower case letters, any capital 
letter standing for an "a” element of the cipher alphabet, and any small 
letter, for a "b" element. Then the external sentence "All is well with 
me today" can be made to contain the secret message "Help". Thus: 

ALl is WJJIL ‘;itn mB TodaY 

aab bb aaba aaba ba abbba 

V ^ . * ^ .V . , / 

H E L P 



^ For a true picture of this cipher, the explanation of which is often dis- 
torted beyond recognition oven by cryptographers, see Bacon's own descrip- 
tion of it as contained in his De Augmentis Scientiarum (The .idvancement of 
Learning) . as translated by any first-class editor, such as Gilbert .<atts 
(1640) or Ellis, opedding, and Heath (1857, 1870). The student is cautioned, 
however, not to accept as true any alleged "decipherments" obtained by the 
application of Bacon's cipher to literary works of the 16th century. These 
readings are purely subjective. ' 

p 

~ In the 16th Century, the letters I and J were used interchangeably, as 
were also U and V. 



REF ID : A64644 



- 75 - 

Instead of sMploying such an ojvious device as capital and small letters, 
suppose that an "a" will be indicated by a very sli^'jht shading, or a vsry 
slightly heavier stroke « Then a secret message might easily be thus en- 
folded within an external message of exactly opposite meaning. The number 
of possible variations of this basic scheme is very high. The fact that 
the characters of the cryptographic text are hidden in some manner or other 
has, hov/sver, no effect upon the strict monoalphabeticity of the scheme. 

36. Historically interesting examples. - a. Two examples of histor- 
ical interest will be cited in this connection as illustrations, during 
the campaign for the presidential election of 1376 many cipher messages 
were exchanged between the Tilden managers and their agents in several 
states where the voting \^as hotly contested. Two years later the New for.; 
Tribune^ exposed many irregularities in the campaign by publishing the de- 
cipherments of many of these messages. These decipherments v;ere achieved 
by tv/6 investigators employed by the Tribune, and the plain text of the 
messages seems to show that illegal attempts and measures to carry the 
election for Tilden were made by his managers. Here is one of the messages. 

JaCHSOMVILLS, 1!ov. 16 (1876). 



STO. 7. RANSY, Tallahassee. 

Ppyyemnshyyypimashnsyyssitepaaensh 



n 


s 


s 


e 


u 


s 


s 


h 


n 


s 


m 


m 


P 


i 


y 


y 


s 


n 


P 


P 


y 


e 


a 


a 


P 


i 


e 


i 


S 


S 


y 


e 


s 


h 


a 


1 


n 


s 


-S 


s 


p 


e 


e 


i 


y 


y 


s 


h 


n 


y 


n 


s 


s 


s 


y 


e 


p 


i 


a 


a 


n 


y 


i 


t 


n 


S 


s 


h 


y 


y 


s 


P 


y 


y 


p 


i 


n 


s 


y 


y 


s 


s 


i 


t 


e 


ra 


e 


i 


P 


i 


ra 


m 


e 


i 


s 


s 


e 


i 


y 


y 


e 


i 


s 


s 


i 


t 


e 


1 


e 


p 


y 


y 


p 


e 


e 


i 


a 


a 


s 


s 


i 


m 


a 


a 


y 


e 


s 


P 


n 


s 


y 


y 


i 


a 


n 


5 


s 


s 


e 


i 


s 


s 


m 


m 


P 


p 


n 


S 


P 


i 


n 


s 


s 


n 


P 


i 


n 


s 


i 


m 


i 


m 


y 


y 


i 


t 


e 


m 


y 


y 


s 


S 


P 


e 


y 


y 


m 


m 


n 


s 


y 


y 


s 


s 


i 


t 


s 


P 


y 


y 


P 


e 


e 


P 


P 


P 


m 


a 


a 


a 


y 


y 


P 


i 


i 


t 























Ii'ilngle goes up tomorrovr. 

D, l: iX^jXi. 



Hxaraination of the message discloses that only ten different letters 
are used. It is probable, therefore, that what one has here is a cipher 
v/hich employs a bipartite alphabet and in which combinations of two let- 
ters represent single letters of the plain„text. The message is therefore 
rewritten in pairs and substitution of arbitrary letters for the pairs is 
made, as seen below: 

PH' YY Kl ns HY’ YY PI \IA SH MS YY S5 etc. 

A B C J F’G H d 3 I etc. 

^ Hew York Tribune - -Cxtra Mo. 44 - "The Cipher dispatches" - Nev/ York, 
1879. 




R^J__ ID : A64644 

A triliteral-frequency distribution is then made and analysis of the 
table along the lines illustrated in the preceding section of this text 
yields solution, as follovfs: 



JACKS0HVILLj3, Nov. 16. 



GjIO. jf. FLiNS'f, Tallahassee! 

Have riarble and Coyle telegraph for influential men from Delaware 
and Virginia. Indications of weakening here. Press advantage and \reitch 
3oard. L'Sngle goes up tomorrow. 



DAMIjJL 



b. The other example, using numbers, is as follows: 



JACKSONVILLE, Hov. 17. 



S- PASCO 


and ; 


L . Li . 


L' 


ENGLE 


I- 






















84 


55 


84 


25 


93 


34 


82 


31 


31 


75 


93 


82 


77 


33 


55 


52 


93 


20 


90 


66 


77 


65 


33 


84 


63 


31 


31 


93 


20 


82 


33 


66 


52 


48 


44 


55 


42' 


82 


48 


89 


42 


93 


31 


82 


66 


75 


31 


93 



DANIEL. 

There were, of course, several messages of like nature, and examina- 
tion disclosed that only 26 different numbers in all were used. Solution 
of these ciphers follov;sd very easily, the decipherment of the one given 
above being as follows- 



J iCKSON^/ILLB, Nov. 17. 



5. PASCO and E. M. L' ENGLE: 

Cocke v/ill be ignored, Eagan called in. Authority reliable. 

J.\1IISL. 

c. The Tribune experts gave the follov/ing alphabets as the result 
of their decipherments: 



AA 


S 


0 


EN 




i 


IT 


S 


D 


NS 


S 


E 


PP 


S 


H 


ss 


S 


iJ 


AI 


= 


u 


EP 


- 


C 


klA 


er 


B 


MY 


S 


il 


SH 


a 


L 


YE 


sr 


F 


El 


s 


I 


lA 


X 


K 


LiM 


B 


G 


PE 


«5 


T 


3N 


s 


P 


YI 


at 


X 


E1.'I 


- 


V 


IH 


= 


S 


NN 


r 


J 


PI 


r 


R 


SP 


= 


\I 


YY 


S 


A 


20 


C8 


D 


33 


a 


N 


44 




H 


62 


V 


X 


77 


a 


G 


89 


at 


Y 


25 


rs. 


K 


34 


- 


\/ 


48 


r 


T 


66 


= 


A 


82 


a 


I 


93 


a 


S 


27 


w 


S 


39 


a 


P 


52 


B 


U 


68 




F 


84 


m 


C 


96 


s 


M 


31 


r 


L 


42 


a 


A 


55 


S 


0 


75 


a 


B 


87 


X 


V 


99 


8 


J 



REF ID : A64644 



- 77 - 



They did not attempt to correlate these alphabets, or at least they say 
nothing about a possible relationship. The present author has, howe^yer, 
reconstructed the rectangle upon i7hich these alphabets are based," and it 
is given herewith! 



2d Letter 
or 

Number 







H 


1 


s 


p 


A 


Y 


u 


E 


N 


T 






1 


2 


3 


4 


5 


6 


7 


8 


9 


0 


H 


1 


Z 


■ 


■ 














n 


I 


2 


■ 


■ 


m 


■ 


m 


■ 


B 


■ 


■ 


El 


S 


3 




■ 


m 


m 


m 


■ 


i 


■ 




■ 


P 


4 


■ 


El 


■ 


fH 


m 


■ 


■ 


Q 


■ 




A 


5 




m 


■ 


■ 


Q 


■ 


■ 


■ 


■ 




y 


6 




Q 


■ 


■ 


■ 


E! 


■ 


13 






M 


7 




m 


■ 


■ 


m 


1 


m 


■ 






E 


8 




s 


■ 


m 


■ 


i 


□ 


■ 


Y 




N 


9 




i 


m 


m 


■ 


1 






E3 




T 


0 




u 


□ 


L 


_ 


i 






■ 





It is fusing, to note that the conspirators selected as their key a phrase 
quite in keeping with, their attempted illegalities; HIS PAYiijlNT; for 
bribery seems to have played a considerable part in that campaign. The 
blank squares in the diagram probably contained proper names, numbers, etc. 

SilCTION VIII 



rODfLITSRAL SUBSTITUTION WITH POLY-S'JUIVALiSNT CIPHjJR ALHIaBETS. 



rurpose of providing poly-equivalent cipher alphabets , . 

Solution of a 'simple example ;.....! 

Solution of a more complicated example .......... 

A subterfuge to prevent decomposition of cipher text into 
component units 



‘ Paragraph- 
. • 37 ' 

. 38 

. 39 



40 



37-. Purpose of providing poly- equivalent cipher alphabets. - a. It 
has been seen that the characteristic frequencies of letters composing 
normal plain text, the associations they form in combining to form v/ords, 
and the peculiarities certain of them manifest in such text all afford 
direct clues by means of which ordinary mOnoalphabetio substitution encipher- 
ments of such plain text may be more or less speedily solved. This has led 
to the introduction of simple methods for disguising or suppressing the 
manifestations of monoalphabeticity, so far as possible. Basically these 
methods are polyliteral arid they will now be presented. 



REF ID:A64644 



- 78 - 



b. Polyliteral substitution may be of two types; 

(l) That wherein each letter of the plain text is 
represented by one and only one polyliteral 'equivalent. 

For example, in the Francis Bacon cipher described in 
Par. 35 e, the letter Kp is invariably represented by 
the permutation ab aab . For this reason this type of 
system may be more completely described as monoalphabet ic, 
polyliteral substitution with monc-eouivale nt cipher 
alphabets . 



(2) That wherein, because of the large number of 
equivalents made available by the combinations and per- 
mutations of a limited number of elements, each letter 
of the plain text may be Pepresent-ed by several poly- 
literal equivalents which may be selected at random. 

For example, if 3-1'etter combinations are emp?.oyed there 
are available 26^ or 17,576 equivalents for the 26 letters 
of the plain text; they may be assigned in equal numbers 
of different equivalents for the 26 letters, in v/hich 
case each letter would be representable by 676 different 
3-letter equivalents; or they may be assigned on some 
other basis, for example, proportionately to the relative 
frequencies of plain-text letters. For this reason this 
type of system ^y be more completely described as mono - 
alphabetic . polyliteral substituti on v;ith poly-equivalent 
cipher alr h abe ts . Some authors term such a system 
’’simple substitution with multiple .equivalents"; others 
term it mo n o al phabet ic substitution with v ariants . For 
the sake of brevity, the latter designation will be 
employed in this text. 



c. The primary object of monoalphabet ic substitution with variants 
is, as has been mentioned above, to provide several values which may be 
employed at random in a. simple substitution of cipher equivalents for 
the plain-text letters. In this connection, reference is made to section 
X of Special Text 165, Blementary Military Cryptography, wherein several 
of the most common methods for producing and using variants are set forth 

d. A word or two concerning the underlying theory from the cryptana 
lytic point of view of monoalphabetic substitution with variants, may not 
be amiss, 'i/hereas in simple or mono-equivalent, monoalphabetic substitu- 
tion- it is seen that: 

(1) The same letter of the plain text is invariably 
represented by but one and always the same character of 
the cryptogram, Eind 

(2) The same .character of the cryptogram invariably 
represents one and always the same letter of the plain text; 



REF ID:A64644 



- 79 - 

in monoalphabet ic substitution v/ith variants; 

(1) The same letter of the plain text may be 
represented by one or more different characters of 
the cryptogram, but 

( 2 ) The same character of the cryptogram 
nevertheless invariably represents one arid always 
the same letter of the plain text. 

38. Solution of a simple example. - a. The following cryptogram 
has been enciphered by the method explained in Par. 52 b of Special 
Text No. 165, 31ementary Military Cryptography, and the steps in solu- 
tion v;ill now’ be scrutinized. 



GRYPTOGRAI'i 



63321 


09022 


48057 


65111 


88648 


42036 


45235 


09144 


05764 


22684' 


00225 


57003 


97357 


14074 


8^524 


40768 


51058 


93074 


92188 


47264 


09328 


04255 


06186 


79882 


85144 


45886 


32574 


55136 


56019 


45722 


76844 


68350 


45219 


71649 


90528 


65106 


11886 


44044 


89669 


70553 


18491 


06985 ■ 


48579 


33684 


50957 


70612 


09795 


29148 


56109 


08546 


62062 


65509 


32800 


32568 


97216 


44282 


34031 


84989 


68564 


53789 


12530 


77401 


68494 


38544 


11368 


87616 


56905 


20710 


58864 


67472 


22490 


09136 


62851 


24551 


35180 


14230 


50886 


44084 


06231 


12876 


05579 


58980 


29503 


99713 


32720 


36433 


82689 


04516 


52263 


21175 


06445 


72255 


68951 


86957 


76095 


67215 


53049 


08567 


9730 





b. Assuming that the foregoing remarks had not been made and that 
the cryptogram has just been submitted for solution with no information 
concerning it, the first step is to make a preliminary study to determine 
whether the cryptogram involves cipher or code. The cryptogram appears 
in 5-figure, groups, which may indicate either cipher or code. A few re- 
marks will' be' made at this point with reference to the method of determin- 
ing whether a' cryptogram composed of figure groups is in code or cipher, 
using the foregoing example. 

c. In the first place, if the cryptogram contains an even number 
of digits, as for example 330 in the foregoing message, this leaves open 
the possibility that it may bo cipher, composed of 165 pairs of digits; 
’.vera the number of digits an exact odd multiple of five, such as 125, 

135, etc., the possibility that the cryptogram is in code of the 5-figure 
group type must bo considered. Noxt, a preliminary study is made to see 
if there are many repetitions, and vAiat their characteristics are. If 
the cryptogram is code of the 5-figure group typo, then such repetitions 
as appear should gen er ally be in whole groups of five digits, and they 
should bo visible in the text just as the message stands, unless the code 
message has undergone encipherment also. If the cryptogram is in cipher, 
then the repetitions should extend beyond the 5-digit groupings; if they 



REF ID : A64644 



- 80 - 

conform to any definite groupings at all they should for the most part 
contain oven numbers of digits since each latter is probably represontod 
by a pair of digits. If no duos of tho foregoing nature arc present, 
doubts will be dissolved by making a detailed study of frequencies. 

d. A simple 4-part frequency distribution is therefore decided upon. 
Shall tho alphabet bo assumed to bo a 25- or a 26- character one? If the 
former, then tho 2-digit pairs from 01 to 00 fall into exactly four groups 
each corresponding to an alphabet. Since this is tho most common scheme 
of drawing up such alphabets, let it bo assumed to bo true of tho present 
case. The following distributions result from tho breaking up of the 
text into 2-digit pairs. 



01 -/// 


26 -/// 


51 


76 -/iiii 


02 - 


27 - 


52 -/Uj 


11 -/ 


03 -//// 


28 -/ 


53 -/// 


78 - 


04 -/ 


29 -/ 


54 - 


79 -/ 


05 


30 -/// 


55 -//// 


80 -/// 


06 -mi! 


31 - 


56 -/Hi 


81 - 


07 -/// 


32 -/MiJ 


57 -tun 


82 - //// 


03 - 


33 -/ 


58 -// 


83 -/ 


09 -//// 


34 -/ 


59 - 


84 -/Hi/ 


10 -//// 


35 -// 


60 - 


85 -/Hi/ 


11 -/HJ 


36 -/HZ 


61 


86 ./// 


12 -/// 


37 - / 


62 -// 


87 - 


13 -/ 


38 - 


63 - 


88 -//// 


14 -/ 


39 -t 


64 -/Hi ! 


89 -(Hi 


15 -/ 


40 -/// 


65 - 


90 -/Hi i 


16 -/// 


41 - 


66 - / 


91 -/// 


17 - 


42 -//// 


67 .// 


92 -/ 


18 -mj! 


43 -/ 


68 - /Hi il 


93 -/ 


19 - 


44 -/Hil 


69 -// 


94 -/ 


20 -/ 


45 -IH/I 


10 -j 


95 -/// 


21 -// 


46 -/// 


11-1 


96 - 


22 -/Hi 


47 - 


72 - //// 


- fHi ! 


23 -// 


48 -/// 


73 - 


98 - / 


24 - 


49 -ff// 


74 -HU 


99 - 


25 -/ 


50 


75 -/ 


00 -// 



Fig. 16 

0 . If the student will bring to boar upon this problem tho principles 
ho learned in Section V of this text, ho will soon realize that what ho 
nov; has before him are four, simple, monoalphabotic froquency distributions 
similar to those involved in a monoalphabotic substitution cipher using 
standard cipher alphabets. Tho realization of this fact immediately pro- 
vides tho clue to tho next stops "fitting each of tho distributions to 
the normal" (Soo Par. 17 b) . This can be done without difficulty in this 
case (romomboring that a 25-lotter alphabet is involved and assuming that 



T 



KEF ID:A64644 



- 81 - 



I and J aro tho samo lottor) and tho following alphabets result; 



01 


- 


I-J 


26 


- 


ir 


51 




N 


- 76 


- 


B 




f. Tho koyv/erd 


. is 


soon to 


02 




K 


27 




V 


52 




O' 


•-77 


- 


F 


bo 


JONS and 


tho 


first fow groups 


03 




L 


28 


- 


w • 


53 


' 


P 


78 


- 


G 


of 


tho cryptogram dociphor as 


04 


— 


M 


29 




X 


54 


- 


Q 


79 


- 


H 


follows : 










05 




N 


30 


- 


y 


55 


- 


R 


80 




I-J 














06r 


k. 


0 


31 


- 


z 


56 




S 


81 




K . 


• 68 


32 10 


90 


22 


48 


05 76 51 


07 




P 


32 


• 


A 


57 




T 


82 


- 


L 


5 


A S 


T 


iB 


R- 


N B N 


08 




Q 


33 




B 


58 


— 


U 


83 


- 


M 














09 




R 


34 


- 


C 


59 


- 


V 


84 


- 


N 


11 


88 64 


84 


20 


36 


45 23 


10 


— 


S 


35 




D 


60 




W 


85 




0 


T 


R A 


N 


G 


B 


0 F 


11 


- 


T 


36 




B 


61 




X 


86 




P 















12 - U 37 - F 62 - Y 87 - Q g. From tho dotailod pro- 

13 - V 38 - ff 63' - Z 88 - R coduro given above, tho etudont 

14 - 39 - H 64 - A 89 - S should be ablo to draw his own 

15 - X 40 - I-J 65 - B 90 - T conclusions as to tho procoduro to 

16 - Y 41 - K 66 - G 91 - U bo followed in solving cryptograms 

17 - Z 42 - L 67 - D 92 - V produced by methods which aro more 

18 - A 43 - M 68 - S 93 - W or loss simple variations of that 

19 - B 44 - N 69 - F 94 - X just discussod. In this connection 

20 - C 45-0 70 - G ' 95 - Y ■ ho is roforrod to Par. 53 of Special 

21 - D 46 - P 71 - H 96 .t Z Text No. 165, Blomontary Military 

22 - B 47 - Q 72 - I-J 97 A . _ Cryptography, whoroin a fow of 

23 - F • 48 - R 73 - K 98 - B . thoso variations aro montionod. 

24 - G 49 - S 74 - L 99 - C 

25 - H 50 - T 75 - M 00 - D 39. Solution of a moro com- 

Fig. 17 plicatod example. - a. As soon as 

a boginnor in cryptography roalizos 

the consequences of the fact that letters aro usod with groatly varying 
frequencies in normal plain text, what seems to him as a now idea very 
speedily comes to him. Vilhy not disguise tho natural froquoncios by a system 
of substitution using many oquivalonts, and lot tho numbers of oquivalonts 
assigned to tho various lottors bo moro or loss in direct proportion to 
tho normal froquoncios of tho lottors? Lot B, for example, have 13 or 
moro oquivalonts; T, 10; N, 9; oto., and thus (ho thinks) tho enemy cryp- 
tanalyst can have nothing in tho v/ay of tcll-talo or charactoristic fro- 
quoncios to uso as an entering wodgo. 

b. If tho text available for study is small in amount and if tho 
variant values aro wholly- indopondont of one another, tho problem can bo- 
come oxcoodingly difficult. But in practical military communications such 
mothods are raroly oncountorod, bo cause tho volume of toxt is usually groat 
enough to pormit of tho ostablishmont of oouivalont . valuos . To illustrate 
v;hat is moant, suppose a, sot of cryptograms produced by tho monoalphabotic- 
variant method doscribod above shows tho following two sots of groupings in 
tho toxt; ■ 



REF ID:A64644 



- 82 - 



Sot A 



Sot B 



12-3'7-02-79-68-l3-03-37-77 

82-69-03-79-13-68-23-37-35 

82-69-51-16-13-13-78-05-35 

91-05-02-01-68-42-78-37-77 



71-12-02-51-23-05-77 

11-82-51-02-03-05-35 

11-91-02-02-23-37-35 

97-12-51-03-78-69-77 



An examination of those groupings vrould load to the follov/ing tentative 
concluBions with regard to probable equivalents s 



12, 82, 91 
05, 37, 69 
02, and 51 



01, 16, 79 
13, 42, 68 



03, 23, 78 
35, and 77 



The establishment of those equivalencies would sooner or later load to 
the finding of additional sots of equal values. The completeness with 
which this can bo accomplished will determine the ease or difficulty of 
solution. Of course, if many equivalencies can be established the problem 
can then bo reduced practically to raonoalphabotic terms and a speedy solu- 
tion can be attained. 



c. Theoretically, the determination of cquiv.alencies .may seem to bo 
quite an easy matter, but practically it may be very difficult, because 
the cryptanalyst can never be certain that a combination showing what may 
appear to be a variant value is really such, and is not a different wordt 
Ftr example, take the groups 

17-82-31-82-14-63, and 
27-82-40-82-14-63 

Hero one might suspect that 17 and 27 represent the same letter, 31 and 
40 another letter. But it happens that one group roprosonts the v/ord 
MANAOa, the other DAI^AGE. 

d. Vi/hon reversible combinations are used as variants, the problem 

is perhaps a bit more simple. For example, using the accompanying Fig. 18 
for encipherment, two messages vjith the same initial words, R3FERENGB YOUR, 
may be enciphered as follows: 





K,Z 


Q>v 


B,H 


M,R 


D,L 


CO 


N 


H 


A 


0 


E 


F,X 


D 


T 


M 


F 


P 


G,J 


Q 


B 


U 


I 


V 


C,N 


G 


X 


R 


G 


S 


P,T 


Z 


L 


Y 


W 


K 



Fig. 18 




REF ID:A64644 



- 83 - 

REFER SNC E Y 0 U R 

(1) N H Vir D R X L S H C D ’7 V/ Z N R S L H P S R B J C H 

(2) C H D W R X S L H N D Z Vf N R L S H P R V/ J B N H 

The experienced cryptanalyst, ncting>the appearance of the very first 
few groups, assumes that he. is here con, fronted vrith a case involving 
biliteral reversible equivalents, with variants. 

e. The probable- wf“rd method of solution may be used, but with a 
slight variation introduced by virtue of t.he fact that, regardless of 
the system, letters of low frequency in plain text remain infrequent . 

Hence, suppose a word containing low-frequency letters, but in itself 
a rather common word strikingly idiomorphic in character is sought as 
a "probable word"; for example, words such as CAVALRY, ATTACK, and 
PREPARE. '.7riting such a word on a slip of paper, it is slid one interval 
at a time under the text, which has been marked so that the high and low- 
frequency characters are indicated. Each coincidence of a low-frequency 
letter of the text with a low-frequency letter of the assumed word is ex- 
amined carefully to see whether the adjacent text letters correspond in 
frequency .with the other letters of the assumed word; or, if the latter 
presents repetitions, whether there are correspondences between repeti- 
tions in the text and those in the word. Many trials are necessary but 
this method will produce results when the difficulties are otherwise too 
much for the cryptanalyst to overcome. 

40. A subterfuge to prevent decomposition of cipher text into com- 
ponent units. - a. A few T/ords should be added with regard to certain 
subterfuges which are sometimes encountered in monoalphabet ic substitution 
with variants, and v/hich, if not recognized in time, cause considerable 
delays. Those have to deal v/ith the insertion of nulls so as to prevent 
the cryptanalyst from breaking up the text into its real cryptographic 
units. The student should take caroful note of the last phraso; the more 
insertion of symbols having tho same characteristics as the symbols of the 
cryptographic text, except that they have no moaning, is not \;hat is meant. 
This class of nulls rarely achieves tho purpose for which they are intended. 
’That is really meant can best be explained in connection with an example. 
Suppose that a 5 x 5 checkerboard design v/ith tho row and indicators shown 
in Fig, 19 is adopted for encipherment. Normally, the cipher units would 
consist of 2-lottor combinations of tho indicators, invariably giving the 
row indicator first (by agreement). 



REF ID : A64644 



- 84 - 



V G I IV D 

A H P S M 

T 0 B . B N 

F U R L C 

V,A,T ,F 
G,H,0,U 
I,P,E,R 
\V,S,B,L 
0 , 1 . 1 , 14,0 



The phrase GOIflMANDER OF SPECIAL TROOPS might be enciphered thus: 

G 0 M M A N D E R 0 F 

VI EB PH lU FT IE AB Tli ’VO E\V GT 



A 


B 


C 


D 


E 


F 


G 


H 


I-J 


K 


L 


M 


N 


0 


P 


Q 


R 


S 


T 


U 


V 


W 


X 


Y 


Z 



Fig. 19 



These would normally then be arranged in 5-letter groups, thus: 

VISBP HIUFT lEABT'M'VOP’/ GT... 

b. It will be noted, however, that only 20 of tho 26 letters of the 
alphabet have been employed as row and column indicators, leaving J, K, 

3, X, Y, and Z unused. Now suppose those five letters are used as nulls, 
not in pairs , but as individual letters insertod at random just before 
the real text is arranged in 5-lettor groups. Occasionally, a pair of 
nulls is insertod. Thus, for example: 

VIEXB PHKIU FJXTI SAJBT MWOQP V/GKTY 

The cryptanalyst, after some study, suspecting a biliteral cipher, pro- 
ceeds to break up tho text into pairs: 

VI EX BP HK lU FJ XT IE AJ BT OQ FJ GK TY 

Compare this sot of 2-lottor combinations with tho correct sot. Only 3 
of the 15 pairs aro "proper” units. It is easy to soo that v/ithout a 
knov/lodge of the oxistonco of tho nulls, and oven with a knowledge, if ho 
does not know which letters aro nulls, tho cryptanalyst would bo confronted 
with a quite difficult problem, for the solution of which a very largo 
amount of text might be necessary. Tho careful omploymcnt of tho variants 
also very materially adds to tho security of tho method because ropoti- 
tions can be rather effectively suppressed. 




KEF ID:A64644 



^ , -^ 95 - 

; , 4 , 'From the cryptographic standpoint, the fact that in this system 
the cryptographic text is more than twice as long as the plain text con- 
stitutes a serious disadvantage. From the cryptanalytic standpoint, the 
masking of the cipher units constitutes the most important source of 
strength of the system; this, coupled with the use of variants, makes it 
a quite llifficult system to solve, despite its monoalphabet icity. 

- 4 cl 
* • . 

83CTI0N IX 



■' ' -POLYGRAHIIG SUBSTITUTION SYSTEMS 

' ■ .'7 

Paragraph 

Monographic and polygraphic substitution systems . 4-1 

Tests for identifying digraphic substitution 42 

General procedure in the analysis of digraphic substitution ciphers 43 
Analysis of digraphic substitution ciphers based upon 

4-square checkerboard designs . 44 

Analysis of ciphers based upon other types of checkerboard designs 45 
Analysis of the Playfair cipher system ..... 46 

41. Monographic and polygraphic substitution systems. - a. The 
student is now referred to Sections VII and VIII of Special Text No. 166, 
Advanced Military Cryptography, wherein polygraphic systems of substitu- 



tion are discussed from the cryptographic point of view. These will now 
be discussed from the cryptanalytic point of view. 

. b. Although the essential differences between polyliterul and poly- 
graphic substitution are treated with some detail in Pars. 29 and 30 of 
Special Text No. 166, a fev/ aaditional words on the subject may not be 
amiss at this point. 

The two primary divisions of substitution systems into (1) mono- 
literal and polyliteral methods and into ( 2 ) monographic and polygraphic 
methods are both based upon considerations as to the number of elements 
-constituting the plain-text and the equivalent cipher-text units. In 
monoliteral as well as in monographic substitution, each plain-text unit 
ccfnsis'ts’ of a single element and each cipher-text unit consists of a 
single element. The two terms monoliteral and monographic are therefore 
identical in significance, as defined cryptographically. It is when the 
terms polyliteral and polygraphic are examined that an essential difference 
is seen. In polyliteral substitution the plain-text unit alv/ays consists 
of a single element (one letter) and the cipher-text unit consists of a 
group of two or more elements; when bilitoral, it is a pair of elements, 
when triliteral, it is a set of three elements, and sc on. In what will 
herein be designated as true or complete polygraphic substitution the 
plain-text unit consists of two or more elements forming an indivisible 
c Propound i the cipher-text unit usually consists of a corresponding number 



REF ID:A64644 

86 - 



of elements. When the number of elements comprising the plain-text 
units is fixed and alv;*-.y.s two, the system is digraphic t when it is always 
three, the system is trigraphic . and so on.^ It is impertant to note 
that in true or complete polygraphic substitution the elements combine 
to form indivisible compounds having properties different from those of 
either of the constituent letters. For example, in monoliteral substitu- 
tion ABp may yield XY^ and AC^ may yield XZgj but in true digraphic sub- 
stitution 3Hp may yield XTj, and jStfp may yield A difference in 

identity of one letter affects the whole result. An analogy is found 
in chemistry, when tv/o elements combine to form a molecule, the latter 
usually having properties quite different from those of either of the 
constituent elements. For examples sodium, a metal, and chlorine, a 
gas, combine to form sodium chloride, common table salt. Furthermore, 
sodium and fluorine, also a gas similar in many respects to chlorine, 
combine to form sodium fluoride, which is much different from table salt. 
Partial and pseudo-polygraphic substitution will be treated under sub- 
paragraphs d and e belov/. 

d. Another way of looking at polygraphic substitution is to regard 
the elements comprising the plain-text units as being enciphered indi- 
vidually and polyo.lphabeticaily by a fairly large number of separate 
alphabets. For example, in a digraphic system in v/hich 676 pairs of plain- 
text letters are representable by 676 cipher-text pairs assigned at random, 
this is equivalent to having a sot of 26 different alphabets for encipher- 
ing one member of the pairs, and another set of 26 different alphabets for 
enciphering the other member of the pairs. According to this viev/point 
the different alphabets are brought into play by the particular combination 
of letters forming each plain-text pair. This is, of course, quite differ- 
ent from systems whorein the various alphabets are brought into play by 
more definite rules; it is perhaps this very absence of definite rules 
guiding the selection of alphabets which constitutes the cryptographic 
strength of this typo of polygraphic system. 

o. Vftien regarded in t,he light of the preceding remr.rks certain 
systems which at first glance seem to be polygraphic, in that groupings 
of plain-text letters are treated as units, on closer inspection are seen 



The qualifying adverb "usually” is employed because this correspondence 
is not essential. For example, if one should draw up a set of 676 arbi- 
trary single signs,' it would bo possiblo to represent the 2-lettor pairs 

from AA to ZZ by single symbols. This would still be a digraphic system. 

.. . - 

In this sense a code system is merely a polygraphic substitution system 
in which the number of elements constituting the plain-text units is vari- 
able. 

3 

For this reason the two letters are marked by a ligature, that is, by a 
bar across their tops. 



REF ID:A64644 



^ “ 

be nnly partially polygraphic, or pseudc-polygraphic in character. 

I’or example, in a' system in which encipherment is by pairs and yet one 
of the letters in each pair is enciphered monoalphabetically , the other 
letter', polyalphabetically, the method is only pseudo- polygraphic . Cases 
^YP® ®^^® s^iown in Par. 31 of Special Text No. 166, Advanced Mili- 
ts.ry tlrypxcgra'phy. Again, in a system in which encipherment is by pairs 
and' the encij)herraents of the left-hand and right-hand metnbers of the pairs 
show” group’ relationships, this is not pseudo-polygraphic but only partially 
polygVaphi’c . ‘ Oases of this type are shown in Pars. 33 - 37, Special Text 
No. 166. 

f . The fundamental purpose of polygraphic substitution is again the 
suppression ef the frequency characteristics of plain text, just as is 
the case in mon’balphabetic substitution with variants; but here this is 
acc6mpTished by a different method, the latter arising from a somewhat 
different approach ,to the problem involved in producing cryptographic se- 

, cyri^. When the substitution involves replacement of single letters in 
a ntofip'alpTiab'et ic system, the cryptogram can be solved rather readily. 
Basically the reason for' this is that the principles of frequency and the 
l^wp .of probability, applied to individual units of the text (single 
3,e^t”e rsJ , have a very good opportunity to manifest themselves. A given 
vbTui^^of text of say V ^a'ihltext letters, enciphered purely monoalphabeti- 
e^ly,^’a/fords n' cipHer characters', and the same number of cipher units. 

Jh? s^'e ‘volume of te'xt , enciphered digraphically, sfiH affords n cipher 
characters but only n cipher units. Statistically speaking, the sample 

m 1 : ■ -V , 2 

within 'which the laws of probability now apply has been cut in half. 
Furthermore, from the point of view of frequency, the very noticeable 
,divers^y in the frequencies of individual letters, leading to the marked 
c'r,esth arid' troughs of the monoliteral frequency distribution is no longer 
so st’rf'tingi'y in evidence in the frequencies of digraphs. Therefore, 
although true digraphic encipherment, for example, cuts the cryptographic 
textiiar units' ^in half, the difficulty of selution is not doubled, but, 
if a"m^i£er of* judgment arising from practical experience can be expressed 
or[ approximated mathematically, squared or cubed. 

g. Sections VII and VIII of Special Text Nr. 166 ‘show various methods 
for the derivation of polygraphic equivalents and for handling these 
equivalents in cryptographing and decryptographing messages. The most 
practicable of those methods are digraphic in character and for this reason 
their solution will be treated in a somewhat more detailed manner than 
will trigraphic methods. The latter can be passed over with the simple 
statement, that their analysis requires much text to permit of solution by 
the frequency method, and hard labor. Fortunately, they are infrequently 
encountered 'because they are difficult to manipulate without extensive 
tables.^ If the latter are required they must be compiled in the form of 



^A patent has been granted upon a rathor ingenious machine for automati- 
cally accomplishing true polygraphic substitution, but it has not been 
placed upon the market. See U. S. Patent No. 1,845,947 issued in 1932 to 
"Weisner and Hill. In U. S. Patent No. 1,515,680 issued to Henkels in 1924, 
there is , described a mechanism which also .produces polygraphic substitution. 



REF ID:A64644 



.. 88 - 

a book or pamphlet. If one is willing to go that far, one might as well 
include in such document more or less extensive lists of words and phrases, 
in which case the system falls under the category of code and not cipher. 

42. Tests for identifying digraphic substitution. - a. Tha tests 
which are applied to determine whether a given cryptogram is digraphic in 
character are usually rather simple. If there are plenty of repetitions 
in the cryptogram and yet tha monolitoral-frequency distribution gives no 
clear-cut indications of monoalphabeticityj if most of tho repetitions 
contain an even number of letters} and if tho cryptogram contains an even 
number of letters, it may be assumed to bo digraphic in nature. 

b. The student should first try to determine v/hether the substitu- 
tion is completely digraphic, or only partially digraphic, or psoudo- 
digraphic in character, as aro the cryptograms produced by the methods 
indicated in Par. 31 f to i of Special Text No. 166, Advanced Military 
Cryptography. As mentioned above, there are cases in which, although the 
substitution is effected by taking pairs of letters, one of tho members 

of the pairs' is enciphered monoalphabotically, tho other member, nolyalpha- 
botically. A distribution based upon tho letters in the odd positions and 
one based upon those in the. even positions should bo made. If one of these 
is clearly monoalphabet ic , then this ovidenco’ that tho message represents 
a case pf psoudo-digraphisra of the type horo described. By attacking tho 
monoalphabotic portion of the messages, solution can soon be reached by 
slight variation of tho usual method, the polyalphabetic portion boing 
solved by the aid of the context and considerations based upon tho probable 
nature of the substitution chart (soo Tables 2, 3, and 4 of Special Text 
No. 166). It will bo noted that tho charts roforrod to show definite 
symmetry in thoir construction. 

c. On the other hand, if tho foregoing stops prove fruitless, it may 
bo assumed that tho cryptogram is complotoly digraphic in character. 

d. Just as certain statistical tests may bo applied to a cryptogram 
to ostablish its monoalphaboticity , so also may a statistical tost bo 
applied to a cryptogram for tho purpose of establishing its digraphicity. 
Tho nature of this tost and its method of application will bo discussed 
in a subsequent text, 

43. Gonoral procedure in tho analysis of digraphic substitution 
ciphers. - a. Tho analysis of cryptograms which have boon produced by 
digraphic substitution is accomplishod largely by tho application of the 
siinplo principles of frequency of digraphs, with t,ho additional aid of 
such special circurastancos as may bo known to or suspected by tho cryptana- 
lyst. Tho latter refer to peculiarities which may bo tho result of tho 
particular method employed in obtaining the equivalents of tho plain-text 
digraphs in tho cryptographing process. In gonoral, however, only if 
there is sufficient text to disclose the normal phonoinona of repetition 
will solution be feasible or possible. 



REF ID:A64644 



i 



-» 89 - 

I ^ 

Howovor, whon a digraphic systom is omployod iri regular service, 
there is little doubt but that traffic will rapidly accijraulato to an 
amount more than sufficient to permit of solutdon by simple principles of 
frequency. Sometimes only two or throe long messages, or a half dozen of 
avdrago length are sufficient. For with the identification of only a few 
cipher digraphs, larger portions of messages may be read because the skele- 
tons of words formed from the few high-frequency digraphs very definitely 
limit the values that ban be inserted for the intervening unidentified 
digraphs. For example’, suppose that the plain-text digraphs TH, ER, IN, 

IS, OF, NT, and TO have been identified by frequency considerations, cer- 
roborated by a tentatively identified 16‘ng repetition; and suppose also 
that the enemy is known to be using a method which yields reciprocal equiva- 
lents between plain and cipher-text digraphs, as for instance the quadri- 
cular table shown in i%"r. 31 a of Special Text No. 166. Suppose the message 
begins as follows (in which the assumed values have been inserted): 



XQ 


VO 


ZI 


LK 


A^ 


OL 


ZX 


PV QN ‘lli 


OL 


UK AL HN 


LK VL 


FO 




TH 


IN 




NT 




RE 


NT 


NO 


IN 


BN 


OZ 


KU 


DY 


EL 


LH 


Y*;/ 










SI 




ON 


TO 

















The words FOURTH INFAtWRY REGIMSOT are readily recognized. The reciprocal 
pairs e1j|, and suggest" ATTACK. The beginning of the message is now com- 

pletely disclosed: ■ FOURTH' INF AIWRY RSGDffiNT NOT YET IN POSITION TO ATTACK. 
The values more or less automatically determined are VO a UR , AL^ r TY , 

HN^ a BT„, VL = P0„,' OZ^ a Ti , = CK„. ^ 

c p’ c p’ c p’ c p 

,£. . Once a good start has been made and a few words have been solved, 
subsequent work is quite simple and straightforward. A knowledge of enemy 
correspondence, including data regarding its most common words and phrases, 
is of great assistance in breaking down new digraphic tables of the same 
nature but with different equivalents 

The remarks, made in above also apply to the details of solution 
in cases of partially digraphic substitution. 



I 44. Analysis of digraphic substitution ciphers based upon 4-square 
^■pifieckerboard designs. - a. In Section VIII of Special Text No. 166, 
•^Yp.noed Military Cryptography, there are shown various examples of di- 
graphic substitution based upon the use of checkerboard designs. These 
taay be considered cases of .partially digraphic substitution in that in the 
checkerboard system there are certain relationships between plain-text 
digraphs having common elements and their corresponding cipher-text di- 

f haphs , which will also have commen elements. For example, take the 
ollowing 4-square checkerboard design: 




!• 



4 



REF ID:A64644 



- 90 - 




Here BGp = O'Nq, BOp = OF5, BSp = OPg, BGp " ONq and BTp = ODg. In each 

casa when Bp is the initial letter cf the plain-text pair, the initial 
letter of the cipher-text equivalent is Og. This, of course, is the direct 
result of the method; it means that the encipherment is monoalphabet ic for 
the first half of each of these five plain-text pairs, polyalphabet ic for 
the second half. This relationship holds true for four other groups of 
pairs beginning with Bp. In other words, there are five alphabets employed, 
not 25. Thus, this case differs from the case discussed under Par. 42 b 
only in that the monoalphabeticity is not complete for one half of all the 
pairs, but only among the members of certain groups of pairs. In a com- 
pletely digraphic system using a 676-cell randomized square, (for example, 
the cipher square illustrated in Par. 31 a of Special Text No. 166) such 
relationships are entirely absent and for this reason the system is cryp- 
tographically more secure than the checkerboard system. 

b. From the foregoing, it is clear that when solution has progressed 
sufficiently to disclose a few values, the insertion of letters within the 
cells o'f the checkerboard design to give the plain-text and cipher relation- 
ships indicated by the solved values immediately loads to the disclosure of 
additional Values. Thus, the solution of only a few values soon leads to 
the breakdown of the entire checkerboard design. 

c. ( 1 ) The following example v/ill serve to illustrate the procedure. 
Let the message be as follows t 





iiniifi 









REF.n^ LA64644 



1 


'* 1 2 3* 4 5 


6 7 8 9 ]0 


IL12 1314 


IB 1713 1920 


2L 22 23 24 25 


25 2728 29 30 


A/ 


H> C A P 


G 0 Q 1 L 


B S P K M 


N D U 


K 


E 


0 H Q N 


F 


B 0 R B 


B. 


‘ G'L C H 


Q b'q B 'F 


H A F X 


S I 0 


K 


0 


Q Y'F N 


s- 


X U C G Y 


G. 


B E 


X A F B X 


L P M X H 


H R 0 


K 


0 ■ 


Q k'Q M 


L , 


F E Q b I 


B. 


U 

G 0 I H M 


U E 0 R i) 


C L T U F_ 


B„ Q...Q 


G 


G 


Q N H F 


X 


I F B E X 

i 


E. 


• f 

' 'y L B U Q 


F G H Q 0 


A F T 


X S Y 


C 


B 


E p'f N 


B 


S P K N U 


F. 


q I T X E 


U Q M L F 


E Q 0 I G 


0 I E 


U 


E 


H P I A N 


Y T F L E 


G. 


F E E P I 


D H P C G 


N Q I H R_ 


F H M 


H 


F 


X C K-U 


P 


D G Q P N 


H. 


G B C Q L 


q P N F N 


P N I T 0 


R T E 


N 


C 


• B G N 


T 


F H H A Y 


I. 


. a L Q'.G i 


A A I Q U 


C H T P G 


B I F 


G 


W 


K F C Q 


S 


L Q M G E 


J. 


¥ Y G R Q 


Q D P R X 


F N Q M L 


FID 


G 


c 


G G I 0 


G 


0 I H H F 


K. 


I R G G G 

■ti,. — . 

G I 


G N D L N 


0 Z T F G 


E E R 


R 


p 


I F H 0 


T 


F H H A Y 


L. 


A A I Q’U 


‘C H T P 















( 2 ) The cipher having been tested f'^r standard alphabets 
"(by the method cempleting the normal oemponents) and found t» 
give negative results, a raoneliteral- frequency distribution is 
made* It is as follows* 




ABCDEFGHIJKLMNCPQRSTUVWXY2 
11 15 26 8 16 30 17 22 24 0 S 14 11 18 15 16 33 9 6 11 11 0 1 12 7 3 



Fig. 21 







REF ID : A64644 



- 92 - 



(3) At first glance this may appear to the untrained ey« 
to be a nlo nr alphabetic frequency difetribution but upon cloa’er 
inspection it is noted that aside from the frequencies of four 
or five letters the f requencfi,es _for the remaining letters are . 
not very dissimilar. There are, in reality, no very marked 
crests and troughs, certainly- not as. many a-s would be expected. 

in a monoalphabet ic substitution cipher of equal length. 

• ^ \ 

(4) The message is now carefully examined for repetitions 

of 4 or more letters^. .. are- all of them; 



... —^Frequency 

TFHHAYZLQCIAAIQUGHTP (20 letters) 2 

QMLFEQqiGOI (ll letters) . 2 

XIFB3X (6 letters) " 2 

FEQQ , . 3 

QMLF 3 

BEHM '* . 2 

BSPK 2 

GOIH 2 



Located in Lines . 
H and K 
C and F 
G and D 
0, D, F 
G, F, J 
B and G 
A and E 
_JD_and J 



Since there are quite a few repetitions, two of considerable - 
length, since all but one of them contain an even number of 
letters, and since the message also contains an even number 
of letters, 344, digraphic substitution is suspected. 

The cryptogram is transcribed .in 2-l,etter groups, for greater 
convenience in study. It is as follows: 

Message transcribed in pairs 





1 


2 


3 


4 


5 


6 


7 


a 


9 


10 


11 


12 


13 


14 


15 


A. 


HF 


GA 


FG 


oq 


IL 


BS 


PK 


MN 


DU 


KE 


OH 


QN 


FB 


OR 


UN 


B. 


QO 


LG 


Hq 


Bq 


BF 


Hbl 


AF 


XS 


10 


KO 


qY 


FN 


sx 


MG 


GY 


G. 


XI 


FB 


EX 


AF 


DX 


LP 


MX 


HH 


RG 


KG 


QK 


qM 


LF 


EQ 


Jll 


D. 


GO 


IH 


MU 


EO 


RD 


CL 


TU 


FE 


qq 


GG 


QN 


HF 


XI 


FB 


EX 


E. 


FL 


BU 


QF 


GH 


qo 


qM 


AF 


TX 


SY 


CB 


EP 


FN 


BS 


FK 


NU 


F. 


QI 


TX 


EU 


QM_ 


LF 


Eq 


qi 


GO 




UE 


HP 


lA 


NY 


TF 


LE 


G. 


FE 


SP 


ID 


HP 


GG 


NQ 


IH 


BF 


HM 


HF 


XG 


KU 


PD 


GQ 


PN 


H. 


GB 


CQ 


LQ 


PN 


FN 


PN 


IT 


OR 


TE 


NC 


CB 


CN 


TF 


HH 


AY 


J. 


ZI 


qc 


lA 


AI 


_2LL 


CH 


TP 


CB 


IF 


GW 


KF 


CQ 


RL 


QM 


CP 


K. 


OY 


GR 


Qq 


DP 


RX 


FN 




LF 


ID 


GG 


GG 




GO 


IH 


HF 


L. 


IR 


GG 


GG 


ND 


LN 


OZ 


-TF 


GE 


ER 


RP 


IF 


HO 


TF 


HH 


AY 


M. 


ZL 




lA 


AI 


-SIL 


CH 


TP 



















'kEF ID:A64644 



•» 93 — ‘ 

It is rioted ‘that all the repetitions listed above break up properly 
into "(K^raphs except in one casa^ y.iz. , _.FE^ in lines C, D, and F. 

This s'eems’"father strange, arid at first thought one might suppose 
that a lett er dropped out dr was added in the vicinity of the FEQQ 
in line D. But it is inmediately seen that the FEQQ in line D has 
no relation at .all to the .F SQ Q. in lines C and F, and that the FEQQ 
in line t) is merely an accidental repetition. 

Cs) A digraphic frequency distribution is made and is shown in. 





A 


B 


C 






F 


G 


K 


I 


K 


L- 


M 


N 


0 


P 


Q 


R 


S 


T 


U 


V ViT 


X 


Y 


Z 


A 


■ 


B 


B 


B 


B 


B 


B 


B 


i 


B 


B 


B 


B 


B 


fl 


B 


B 


B 


B 


B 


fl 


B 


Bl 


B 


B 


B 


■ 


B 


B 


B 


B 


B 


B 


B 


i 


B 


B 


fl 


B 


fl 


fl 


B 


B 


B 


fl 


B 


i 


B 


Bl 


B 


B 


C 


H 


B 


B 






B 


B 


B 




fl 


B 


B 


B 


B 


■ 


B 


B 








- 








n 


D 












B 


B 


B 


B 


B 








B 


B 


B 


B 


B 


B 


B 


B 


B 


B 


B 


B 


E 




























B 


B 


B 


B 






1 






2 






F 


■ 


B 






B 






i 






1 




4 






L 





















G 


_ 


B 


B 




1 




1 


i 










B 


B 




B 


fl 


B 




fl 


B 


B 


B 


B 


fl 


H 


■ 


B 


B 




B 


B 




B 








B 




B 


B 


B 








B 


B 


B 


fl 


B 


i 


I 


B 


B 


B 


B 


B 


B 


B 


B 


B 


B 


B 


fl 


B 


B 


B 


B 


B 


B 


B 


B 




B 


B 


B 


B 


K 


B 








B 


B 


B 












B 


B 


B 










1 










I 


L 


B 


B 


B 






B 


B 


B 


B 


B 


B 


fl 


B 


B 


B 


B 


1 


B 


B 


B 


B 


B 






i 


M 


B 


B 


B 




















1 






□ 








1 






B 


B 


IB 


N 




B 


B 


B 




B 


B 


B 


B 


B 


B 


fl 


B 


B 


B 


a 








1 






B 


B 


IB 


0 
















1 








n 




B 


B 


B 


B 






1 


fl 


B 




B 


B 


P 


B 


B 


B 


1 






1 






B 




n 


3 






















i 


□ 


Q 


i 




B 




B 


B 


B 


B 


B 


B 




B 


B 


B 


B 


B 


B 


B 


B 


B 


B 




B 


IB 


IB 


R 




B 


B 


B 


B 


B 


B 


B 


B 


B 


B 


B 


B 


fl 


B 


B 


B 


B 






B 




B 


IB 


IB 


S 




B 


B 


B 


B 


B 


B 


B 


i 


B 


B 


fl 


B 


fl 


B 


i 


B 


B 


B 


fl 


i 




B 


B 


IB 


T 




B 


B 


B 


B 


B 




1 


B 


fl 






B 


fl 


B 


B 


B 


1 


fl 


B 


B 




B 


IB 


IB 


U 




B 


B 


B 


B 


B 


B 


i 


B 


i 






B 


■ 


iB 


B 




i 


i 


IB 


B 




B 


IB 


IB 


V 






L 
























ii 


a 








IB 


1 




IB 




fl 


W 




B 


fl 


B 


B 




















i 


i 








IB 


B 




L 


“1 


1 


X 


B 


B 


B 


B 


B 


B 


B 


B 


B 


B 


fl 


B 


fl 




B 


B 


B 


1 




IB 


B 




B 


IB 


B 


y 


B 


B 


B 


B 


B 


B 


B 


















B 


B 


fl 


B 


IB 


IB 




IB 


B 


B 


z 




[I 




B 


B 


B 


B 




B 


fl 


B 


B 


B 


B 


B 


fl 


B 


B 


B 


IB 


IB 




IB 


B 


B 



4 

• » 




Fig. 22 



REF ID:A64644 

- 94 - 

(e) The appearance of the digraphic distribution for 
this message .is quitq, characteristic of that for a digraphic 
substitution cipher. Thera are many blank cells; although 
there are many cases in which a digraph appears only once, 
there are quite a few in which a digraph appears two or 
three times, four casoa in which a digraph appears four 
times, and two cases in which a digraph appears five times. 
The absence of the letter J is also noted; this is often 
tho case in a digraphic system based upon a checkerboard 
design. 

(7) In another common type «f checkerboard system 
known as the Playfair cipher, described in Par. 46, one 
of the tolltals indications besides the absence of the 
letter J is the absence of double letters, that is, two 
successive identical letter's. Tho occurrence of the double ' 
letters GG, HH and QQ in the message under investigation 
eliminates the possibility of its being a Playfair cipher. 
The simplest thing to assume is that a 4-squaro checker- 
board is involved. One with normal alphabets in Sections 
1 and 2 is therefore set down (Fig. '23 a). 




Fig, 23 a. 

(8) The recurrence of tho group QMLF, three times, 
and at intervals suggesting that it might be a sentence 
separator, loads to the assumption that it is the word 
'STOP. The letters Q, M, L, and F are therefore inserted 
in the appropriate cells in Sections 3 and 2 of the dia- 
gram. Thus (Fig. 23 b ) t 







KEF ID : A64644 




- 95 - 



A 


B 


c 


D 


E 












F 


G 


K 


I-J 


IC 












L 


M 


N 


0 


P 










L 


Q 


R 


S 


T 


U 








Q 




V 


W 


X 


y 


Z 






















A 


B 


c 


D 


E 












F 


G 


H 


I-J 


K 








F 




a 


im 


N 


m 


P 


■ 


■ 


Q 


■ 


■ 


m 


B 


S 


T 


U 


1 


i 


■ 


■ 


■ 


a 


B 


X 


y 


r» 

Zj 



Fig. 25 b 

# 

These placements seem logical. Moreover, in Section 3 the 
number of colls between L and Q is just one less J;han enough to 
contain all the letters M to P, inclusive, and suggests that 
either N nr 0 is in the koyr/ord portion of the sequence, that 
is, near the top of Section 3. V/itlaout making a commitment in 
the matter, suppose bpPh W and 0, for the present, be inserted 
in the ceil between M and P. Thus (Fig. 23 c.) : 



1 


11 


B 


D 


E 


1 


1 






U 


1 


B 


B 


I-J 


K 


i 


i 




B 


B 


L 




B 


0 


P 








B 


B 


JL 


B 


S 


B 


B 


M 


N 

0 


p 


_Q. 





V 


B 


B 


B 


z 




L^_J 










B 


B 


B 


B 


B 


B 


B 


B 


B 




B 


B 


B 


B 


B 


B 


B 


ss 


B 








F 




L 


M 


N 


0 


P 






M 






Q 


R 


S 


T 


u 












V 


y; 


X 


V 


z 



♦ 




Fig. 23 c 





REF ID:A64644 



- 96 - 

(9) Now, if tho placement of P in Section 3 is 
correct, the cipher equivalent of THp will be P6 q, and 
there should be a group of adequate frequency to cor- 
respond. Noting that PN^ occurs throe times, it is as- 
sumed to be THp, and the letter N is inserted in the 
appropriate coll in Section 4. Thus (Fig. 23 d) : 




Fig. 23 d. 

(10) It is about time to try out these as'-.umed 
values in the message. The proper insertions are made, 
with the following results: 

1 2 3 4 6 6 7 8 9 10 11 12 13 14 15 

A. HF CA PG OQ IL BS PK MN DU KE OH QN FB OR UN 

B. QG LC HQ BQ B F HM AF XS 10 KO Q2 FN SX MC GY 



C. XL__ZB._SL 

D. GO I H IjIU 



AF 


DX 


LP 


MX 


EO 


RD 


CL 


TU 



HH RG KG QK 
FE QQ CG QN 



OM LF EQ 01 

BT OP 

HF XI FB EX 



E. 


FL 


BU 


OF 


CH 


CO 


QIvI 

ST 


AF 


TX 


SY 


CB 


EP 


FN 






M 


F. 


QI 


TX 


EU 




LF 


EQ 


QI 


GO 


_IE 


UE 


HP 


lA 


NY 


TF 


LB 


G. 


FE 


EP 


ID 


HP 


0^^ 

CG 


NQ 


IH 




HI4 


HF 


XC 


KU 


PD 


GO 


PN 

TH 

AY 


H. 


CB 


CQ 


LQ 


PN 


FN 


PN 


IT 


OR 


TE 


NC 


CB 


CN 


TF 


HH 






TIT 




TH 




















J. 


3L 


__QC 


lA 


AL. 


QU 


CH 


TP 


CB 


IF 


GW 


KF 


CQ 


SL 


QM 


CB 



ST 



1 




K. 



REF ID:A64644 

* 97 - ■ 



M. 



1 


‘2 


3 


4 


5 


6 


7 


S' 


9 


lo ‘ 


11 


12' 


13 


14 


15 
































OY 


CR 


QQ 


EP 


RX 


FN 




LF 


IE 


GC 


CG 


10 


GO 


IH 


HF 














ST 


OP 
















IR 


CG 


GG 


ND 


LN 


02 


TF 


GE 


ER 


RP 


IF 


HO 


TF 


HH 


AY 

t i 


Sk. 




lA 


AI 


J[LL 


GH 


TP 


' - 

















(11) So far ns impossible combinations are in 
evidence. Beginning with group S4 in the' message is seen 
the following sequences 



.P N F 
T H . 



N P li 

. T A 



Then AT^ 



PIJ , and the letter 
But this is in- 
since N in Section 
in row 2 column 4 



Assume it to be THAT THE. 

’ 'N is to be inserted in row 4 column 1 
consistent with previous assumptions', 

4 has already been tentatively' placed 
of Section 4. Other assumptions for FN„ are made: that 

it is ISp (THIS TH...)j that it is ENp (THEN TH.,.)} but 
the same inconsistency "is apparent. In fact, the student 
:will see that FN^ must represent a digraph ending in F, 
G, H, I-J, or K, since Ng is tentatively located cn the 
line as these letters in Section 2. Now FN^ occurs 
’4 tim.es in the message. The digraph it represents must 
t'be one of the following: 









DF, 


EG, 


EH, 


El, 


EJ, 


EK 














IF, 


IG, 


IH, 


II, 


IJ, 


IK 








1 

•f 1 






JF, 


JG, 


JH, 


JI, 


JJ, 


JK 








•a 






OF, 


OG, 


OH, 


01, 


OJ, 


OK 














TK, 




















» 




YF, 


YG, 


YH, 


YI, 


YJ, 


YK 








Of 


these 


the 


1 only 


''ne 


likely to be 


repeated 4 times is 


OF, 


yielding 


: T H 0 


F T 


H which 


may 


be a part 


of 










P N F 


N P 


' N 










n 




. N 


0 R 


T H 


oft: 


H E 


. nr . 


S 0 


U T 


HOF 


T H 


E . 


* , C,Q 


h Q 


P N 


F N P 


N I 


T 


G 


Q L 




N F N 


P N 


I T 



^ In either case, the position of the F in Section 3 is 
excellent: F . . . L in row 3. There are 3 cells 

intervening bet’ween' F and L, into which G, H, I-J, and 
K may be inserted. It is not nearly so likely that G, 
H, and K are in the keyword as that I should be in it. 



REF ID:A64644 

- 98 - 

Let it be assumed that this is the case, and let the 
letters be placed in the appropriate cells in Section ' 
3. Thus (Fig. 23 e) . 



m 


D 


B 


g 


B 


B 


B 


B 


B 


■ 


n 


B 


B 


g 


B 




B 




i 


II 


i 


M 


B 


B 


B 


B 


B 


B 


g 




m 


g 


B 


B 


g 


ifi 


B 


B 


B 


i 


i 


B 


B 


B 


B 












■ 


B 


B 


B 


B 


B 


B 


B 


B 


B 


i 


B 


B 


B 


B 


B 




B 


IS 


B 




B 


B 


g 


B 


B 




B 


B 


B 


,■ 


B 


El 


B 


B 


B 


B 


B 


g 


B 












B 


B 


B 


i 


D 



Fig. 23 e. 

Let the resultant derived values be checked against the 
frequency distribution. If the position of H in Section 
3 is correct, then the digraph ON^, normally of high fre- 
quency should be represented several times by HF^. Ref- 
erence to Fig. 22 shows a frequency of 4 times. And HMq 
2 occurrences, represents NS^. There is no need to go 
through all the possible corroborations. 

(12) Going back to the assumption that T H , . T H 

P N F N P N 

is part of the expression .NORTHOFTHE.er 

CQLvgpNFNPNIT 

•SOUTHOFTHS. ,itis seen at once from Fig. 
CQLXJPNFNPNIT 



23 B that the latter is apparently correct and not the 
former, because LQ^ equals OU^, and not CR^. If 0Sp = 

this means that the letter G of the digraph CQc must be 
placed in row 1 column 3 or roW 2 column 3 of Section 3. 
Now the digraph occurs 5 times, OGj,, 4 times, CH^ , 3 
times, CQj, , 2 times. Let an attempt be made to deduce 
the exact position of G in Section 3 and the positions 
of B, G, and H in Section 4. 'Since F is already placed 




REF ID:A64644 



] 

f 



i 

t 

r 



- 99 - 



r. in Section 4, assume G and H directly fellow it, .and, 
that B comes before it,' How much before? Suppose a, 
trial be made. Thus (Fig. 23 f ) s 



9 



i t 



I 



A 


B 


G. 


D 


.E 


f 




0 




t 


F 


G 


■H 


LJ 


.K 






G 






L 


M 


N 


0 


‘P 


F 


G 


H 


K. 


L 


.1. 


R 


? 




'U 


M 


N 

Q 


P 


k 


. 


V 


W 


X 


t 


Z 


■ 


1 
















f 


A 


B 


C 


D. 


F 








N 






\k 


‘M 


I-J 


1 


B 


B 


B 


F 


G 


L 


M 


N 


0 


P 


H 






Q 


i 




R 


B 


■T 


U 












V 


W 


X 


Y 


Z 



■ * 5 . i I ‘ 

Fig. 23 f. ■ 

L i 0 if ; 



By referring now to the frequency distribution--, Fig* 22,, 
afier a very few minutes, of .experimentation it.bec.bmes 
apparent that the following Is ccrrocis 

- : 1_Z! 1 C 1! 4_ f '» 







REF ID:A64644 



- 100 - 

(13) The identificatlonc given \s'j these placements are inserted 
in the text, and solution is very rapidly completed. The final checker- 
board and deciphered text art given below. 





A 


B 


C 


1 

D 


E 


S 


0 


iC 




E 






F 


G 


H 


I-J 


K 


T 


Y 


A 


'b 


D 




1 


L 


M 


N 


0 


P 


F 


G 


H 


1 

K 




1 3 




Q 


R 


1 

S 


T 


U 


M 


R 


P 


Q 


R 






x_ 


.7 


X 


y_ 


Z_ 


U 


V 




X 


Z 






E 


X 


P 


u 


L 


A 


B 


C 


D 


E 






S 


I 


1 

0 


N 


A 


F 


G 




I-J 


K 




4 


B 


C 


D 


F 


G 


L 1 


}Li 


N 


0 


P 


2 




H 


K 


k 




R 


9. 


R 


S 


T 


U 






T 


vj 




1 

Y 


Z 


V 




X 


Y 


Z 





. Fig! 23 h. 



A, 


H 


P 


C 


A 


P 


G 


0 


Q 


I 


L 


B 


S 


P 


K 


M 


N 


D 


U 


V 


E 


0 


H 


Q 


K 


F 


B 


0 


R 


U 


N 




0 


N 


E 


H 


U 


N 


D 


R 


E 


D 


F 


I 


R 


S 




F 


I 


E 


L 


D 


A 


R 


T 


I 


L 


L 


E 


R 


Tr 

J. 


F 




Q 


C 


L 


C 


K 


Q 


b 


Q 


b 


F 


H 


M 


A 


F 


X 


S 


I 


0 


K 


0 


Q 


Y 


F 


N 


S 


X 


M 


C 


G 


Y 




R 


0 


M 


P 


0 


S 


I 


T 


I 


0 


H 


S 


I 


N 


V 


I 


C 


I 


H 


I 


T 


Y 


0 


F 


B 


A 


R 


L 


0 


W 


c. 


X 


I 


F 


b 


E 


X 


A 


F 


D 


X 


L 


n 

X 


M 


X 


H 


H 


R 


G 


K 


g' 


Q 


K 


Q 


M 


L 


F 


E 


Q 


Q 


I 




w 


I 


L 


L 


B 


E 


I 


N 


G 


E 


N 


E 


R 


A 


L 


S 


0 


P 


P 


0 


R 


T 


S 


T 


0 


P 


D 


U 


R 


I 


D. 


G 


0 


I 


H 


M 


U 


E 


0 


R 


D 


C 


L 


T 


U 


F 


E 


Q 


Q 


C 


G 


m 


N 


H 


F 


X 


I 


F 


B 


E 


X 




N 


G 


A 


T 


T 


A 


C 


K 


S 


P 


E 


G 


I 


A 


L 


A 


T 


T 


E 


N 


T 


I 


0 


N 


W 


1 


L 


L 


B 


E 


E. 


F 


L 


B 


U 


Q 


F 


C 


H 


Q 


0 


Q 


M 


A 


F 


T 


X 


S 


Y 


C 


B 


E 


P 


F 


B 


B 


S 


P 


K 


N 


U 




P 


A 


I 


D 


T 


0 


A 


S 


S 


I 


S 


T 


I 


N 


G 


A 


D 


V 


A 


N 


C 


E 


0 


F 


F 


I 


R 


S 


T 


B 


F. 


Q 


I 


T 


X 


E 


u 


Q 


M 


L 


F 


E 


Q 


Q 


I 


G 


0 


I 


E 


U 


E 


H 


P 


I 


A 


N 


Y 


T 


F 


L 


B 




R 


I 


G 


A 


D 


E 


S 


T 


0 


P 


D 


U 


R 


I 


N 


G 


A 


i) 


V 


A 


N 


G 


E 


I 


T 


7/ 


I 


L 


L 


P 


G.. 


F 


E 


E 


P 


I 


D 


H 


P 


C 


G 


N 


Q 


I 


H 


3 


F 


II 




H 


F 


X 


n 

u 


K 


U 


P 


D 


G 


Q 


P 


N 




L 


A 


C 


E 


C 


0 


N 


C 


E 




T 


E 


A 


T 


I 


0 


N 


s 


0 


N 


7/ 


0 


0 


D 


S 


N 


0 


R 


T 


H. 


H. 


0 


b 


C 


Q 


L 


Q 


P 


N 


F 


N 


P 


N 


I 


,T 


0 


R 


T 


E 


N 


G 


G 


B 


C 


N 


T 


F 


H 


H 


A Y 




A 


N 


D 


S 


0 


U 


T 


H 


0 


F 


T. 


H' 


A* Y 


E 


R 


F 


A 


R 


LI 


A 


N 


D 


H 


I 


L 


T 

u 


S 


I 


X 


J. 


Z 


L 


Q 


C 


I 


A 


A 


I 


Q 


U 


C 


H 


T 


P 


C 


B 


I 


F 


G 


W 


K 


F 


C 


Q 


S 


L 


Q 


M 


C 


B 




z 


E 


R 


0 


E 


I 


G 


H 


T 


D 


A 


S 


H 


A 


A 


N 


D 


0 


N 


W 


0 


0 


D 


,s 


E 


A 


S 


T 


A 


N 


K. 


0 


Y 


G 


R 


Q 


Q D P R X 


F N Q 


,! L 


F I D G C 


C G I 0 G 


0 I H H F 


t 


D 


W 


E 


S 


T 


T HtER E 


0 F S T 0 


? C. 


) 11 K 


1 


i K C I K 


G A T 0 N 


L. 


I 


R 


C 


G 


G 


G 


N 


D 


L 


N 


0 


Z 


T 


F 


G 


V 


L 


R 


R 


P 


I 


F 


H 


0 


T 


F 


H 


H 


A 


Y 




E 


T 


E 


N 


P 


M 


S 


M 


0 


K 


E 


W 


I 


L 


L_ 


B 


E 


U 


S 


E 


D 


0 


N 


H 


I 


L 


L 


S 


I 


X 


Hi. 


Z 


L 


Q 


C 


I 


A 


A 


I 


Q 


U 


C 


H 


T 


P 




































Z 


E 


R 


0 


E 


I 


G 


H 


T 


D 


A 


S 


H 


A 



































d. (1) It is interesting to note how much simpler the matter becomes 
when the positions of the plain-text and cipher- text sections are reversed, 
or, v/hat amounts to the same thing, v.rhen in encipherment the plain-text 
pairs are sought in the sections containing the mixed alphabets, and their 



f 



RETIE’ IDf A64644 

- 101 - 

cipher equivalents are taken frcu the sections containing the normal 
alphabets. 'For example, referring to Fig. 23 h, suppose that sections 
3-4 be used as the source of the piain-be-xt pairs, and sections 1-2 as 
the source of the cipher-text pairs. Then OKp - DGg, EHp = AUg, etc. 

(2) To solve a message enciphered in that^manner, it is necessary 
merely to make a square in v/hich all four sections are normal alphabets, 
and then perform two steps. . First^ the cipher tejrb pairs are converted 
into their normal alphabet equivalents merely by "deciphering" the mes- 
sage with that square j thu result of this operation yields two mond- 
alphabe-ts, one composed of the odd letters, the other,_^of the even 

, letters. The second step is to solve those t7o_ monoalphabets. , 

(3) 7<hcre the same nixed alphabet is inserted in sections 3 and 4> 
the problem is still easier, since the letters resulting from the conver- 
sion intp normal-alphabet equivalents all. belong to the same,' single- 

. mixed alphabet. 

45. Analysis of ciphers based upon other types of checkerboard 
designs.'- The solution' of cryptograms enciphored by other typos of 
checkerbpard designs is accomplished .along lines very similar to those set 
forth in' the foregoing example of the soluti-on of v. message, prepared by 
m'eans ‘of a 4-square checkerboard design. There arc, tinfortunately, no 
means of, tests which can be applied to determine in the early stages of 
the analysis exactly what type .of design is involved in the first case 
UEfdor stw^y • The author freely admits that the solution outlined in sub- 
paragraph is quite artificial in that nothing is deraonstfated in step 
(7) that obYi-'ously leads to or warrants the assumption that a 4-square 
’ checkerboard is Involved. This point was passed over with the quite bald 
statemepb that this v/as ''the sinpiost thing to assume" - and then the so- 
lution proceeds exactly as though this more hypothesis has been definitely 
cstablishea. For example, the very first results 'obtalnod were based upon 
adsdmirig that a certain 4-lsttor repetition represented the word STOP and 
immediately inserting certain letters in appropris-te cells in a 4-sciuare 
checker’b'oard . Severa.l more assumptions were built on top of that and very 
rapid strides were made. Tilhat if it had not been a 4-square checkerboard 
at all? Yvliat if it h.ad been a 2-seiiarc checkerboard -if the type shown in 
- Fig. 24? 



The only defense that can be made'^of what may seem to the student to be 
ipurely arbitrary procedure based upon the author's advance information 
or‘'knowledge is the following: In the first 'place', in Drder to avoid 

making the cxplrnStion a too-long-dravm-out affair, it is necessary, and 
pedagogical experience warrants, that certain alternabive hypotheses be 
passed over in silence. .Tn the second place, it may now be added, after 
the principles and procedure have been elucidated (which at this stage 
is the primarj' object of this text) that if good results do not follow 
from a first hypothesis, the only thing the cryptanalyst can do is to 



M 


A 


M' 


1 . 

II 


F 


0 


S 


Q 


‘L 


p 


_G_ 


T 


R 


I 


G 


I 


Zi 


y 


V 


X 


B 


B 


ill 


H 


K 


D 


tr 


H 


B 


E 


L 


0 


P 


Q 


s 


A 


p 


11 


n 


N 


V 


Vi 


X 


y 


i, 


T 


G 




c 


R 



Fig. ‘24 



I 



REF ID:A64644 



- 102 - 

reject that hypothesis, and formulate a sec'nd hypothesis. In actual 
practice he may have to reject a second, third, fourth, . . . nth hypothesis. 

In the end he may strike the right one - or he may not. There is no 
guaranty of success in the matter. In the third place, one of the objects 
of this text is to sh«w hcu certain 'systems , if employed for military pur- 
poses, can 'readily be broken down.' Assuming that a checkerboard system 
is in use, and that daily changes in keywords are made, it is possible 
that the .traffic of the first day'might give considerable difficulty in 
solution, if ‘the type of checkerboard ' were hot known to the cryptanalyst. 

But the second or third day's traffic would be easy to solve, because by 
that time the cryptanalytic personnel would have analyzed the system and 
thus learned what type of checkerboard' the enemy is .using. 

46. Analysis of the Playfair cipher system. - a. An excellent example 
of a practical, partially digraphic system is the Playfair cipher.^ 

It was used for a number of years as a field cipher by the British Army, 
before and during the Viforld V/ar, and for a short time,, also during that 
v;ar, by field units of the American Expeditionary Forces*’ 

‘ill, , ' 

b. Published solutions^ for this .cipher are quite similar basically 
and vary only in-rainor details. The earliest, that by Lieut. l%jiborgne, 
used straightforward principles of frequency to establish the values of 
three or four of the most frequent digraphs. • Then, on the. assumption 
that in most cases in which a keyword appears on the first and second rows, 
the last five letters of the normal alphabo.t, Vr/XYZ, will rarely be dis- 
turbed in sequence and will occwpy thelast row of the square, he "juggles" 
the letters i given by the yaluos- tentatirely. established .from frequency 
considerations, placing' them in various positions in the square, together 
with WXYZ, to correspond to the plain-text cipher relationshipSf tentatively 
established." A later solution by Lieut. Frank Moorman, as doscrihed in 
Hitt's Manual, assumes that in a Playfair cipher prepared by means of a 
square in (Vhich the keyword o.ccupies tho first and second rows, if a di- 
graphic frequency distribution is "made, it will be' found thffil; 'the "lettors 
having the .greatest combining power aro very probably letters of" "thp key. 

The latest published- solution by Lieut. Commander Smith, is perhaps the 



This cipher was really invented by Sir Charlos \'\rheatstone but receives 
its name from Lord Playfair, v/ho apparently was its sponsor before the 
British Foreign Office. See Womyss Reid, "Memoirs of Lyon Playfair", 
London, 1899. 



2 

Mauborgne, Lieut. J. 0. An advanced problem in cryptography and its 
solution, Leavenworth, 1914. 

Hitt, Captain Parker. Manual fer the solutiori of military ciphers, 
Leavenworth, 1918. 

Smith, Lieut. Coramand.er W. 'V., U. S,. In "Cryptography" by Andre 
.Langie,' translated by,.I. C, H. Macbet.h, Now Y#rk» 1922. 



REF ID : A64644 

' - 16 ^ - 

nio'fet lucid and systematized of the throe. He sets forth in definite 
language certain considerations whith the other two writers certainly 
entertained but failed to indicate. 

The following details have boon summarized from Commander Smith's 

solutions 

(l) The Plo.yfair cipher may be recognized by virtue of 
tho fact that it always contains an oven number of letters, 

.land that when divided into groups of two letters each, no 
group contains a repetition of the samo letter, as NN or 
.J23. Ropefaitions of digraphs, trigraphs, and polygraphs 
will bo evident in fairly long messages. 

. (2) Using the square^ shown in Fig. 25 a, there are 

two general cases to bo considored, as regards tho results 
of encipherment s 



B 




N 


K 


R 


D 


E 


F 


G 


H 


I-J 


L 


M 


0 


Q 


u 


P 


T 


G 


T 


S 


V 


1 


X 


z 



- Fig. 25 a. 

Case 1. Letters at opposite corners of a rectangle. The following 
relationships are found: 



Reciprocity 

Case 2. Two letters 
relationships are found: 



1 -r- - . 

The Playfair square accempanying Commander Smith's s«luti»n is based 
upon the keyword MNKRUPTCY, "to be distributed between the first and 
fourth iines of the square." This is a simple departure from the "riginal 
Playfair scheme in which the letters of the keyword are written from left 
to right and in consecutive lines from the t»p downward. 



THp = YF^ 

HTp = FY^ 

YFp = TH^ 

- FYp = HT^ 
is complete. 

in the same line or column. The follov;ing 



AN„ a NK„ 
P c 



NAp = 



= KI^. 





REF ID:A64644 

1 r\A 



But NKp does not - ANg, nor does 
KNp ='NAg 

Reciprocity is only partial. 

(3) The foregoing gives rise to the follcwing. 



RULE I: 

(a) Regardless of the position of the letters 
in the square, if 



1.2 - 3.4, then 
2.1 I 4.3 



(b) If 1 and 2 form opposite corners of a rec- 
tangle, the following equations obtain - 

1.2 = .3.4' 

2.1 = 4.3 
3.4 = 1.'2 

4.3 “ 2.1 

(4) A letter considered as occupying a position in 
a row can be combined with but four other letters in the 
same rowj the same letter considered as occupying a position 
in a column can be combined with but four other letters in 
the same column. Thus, this letter can be combined with 
only 8 other letters all told, under Case 2, above. But 
the same letter considered as occupying a corner of a 
rectangle can be combined with 16 other letters, under 
Case 1, above. Commander Smith derives from these facts 
the conclusion that "it would appear that Case 1 is twice 
as probable as Case 2.” He continues thus; 



"Now in the square, note that: 



ANp = NK^ 



EN„ = FA„ 



GN- = FK^ 
P P 



= FL„ 



0N„ = MK^ 
P c 

CN„ = TK 
P c 



also 



ET., = FP„ 



EV/„ = FV, 



XNp « 



EF„ = FG„ 



"From this it is seen that of , 'the 24 equations that 
can be formed when each letter of the square is 'employed 
either as the initial or final letter of the group, five 



REF ID:A64644 



- 105 - 

will indicate a repetition of a corresponding letter 
of plain text. 

"Hence, RUL3 II. - After it has been determined, 
in fhb equation 1.2 = 3.4, that, say, 3Np ts FA^, there 

is a probability of one in five that any other group 
beginning with Fj, indicates EOp, and that any group 
ending in A^. indicates ONp. 

"After such combinations as SR^ ORp and ENp have 
been assumed or determined, the above rule may be of use 
in disco /ering additional digraphs and partial words. "1 

RULE III. - In the equation 1.2 = 3.4, 1 and 3 
can never be identical, nor can 2 and 4 ever be identical. 

Thus, ANp could not possibly be represented by nor 

could ERp be represented by KR^. This rule is useful in 
.elimination of certain possibilities when a specific 
' .message is being studied. 

^ . There is an error in this reasoning. Take, for example, the 24 equations 
having F as an initial letters 



Case ^ Case Case Case 



.1 


FBc = DNp 


2 


FE « ED 


2 


FT s 


1 


FX = 


GW 


2 


Fp * EH 


1 


FL « EM 


2 


rjlv NT 


1 


FR » 


HN 


» -I 


FI s EM 


1 


FP * ET 


1 


FK s GN 


2 


FH « 


EG 


■1 


= DT 


1 


FV « EW 


2 


FG = EF 


1 


FQ = 


HM 


1 


F5 , = DV/ 


2 


FN w M 


1 


FO r GM 


1 


FY s 


HT 


■ 1 


FA ' • EN 


2 


FM sr NF' 


' 1 


FC = GT 


1 


FZ * 


m 


Here 


, the initial 


letter 


Fj, represents the follovring 


initial 0 


P®' 





,! ' D B N G H 

It is seen that F^ represents Dp, Np, Gp, Hp 4 times each, and E^, 8 times. 

Consequently, supposing that it has been determined that FA^ z ENp, the 

probability that F will represent is not 1 in 5 but 8 in 24, or 1 in 

c ^ i* 

3; but supposing that it has been determine! that FIV s NTp, the proba- 
bility that F^ will represent Np is 4 in 24 or 1 in 6. The difference 

in these probabilities is occasioned by the fact that the first instance, 
FAg - ENp corresponds to a Case 1 encipherment, the second instance, 

FW^ - NTp, to a Case 2 encipherment. But there is no way of knowing 
initially, and without other data, whether one is dealing with a Case 1 
or Case 2 encipherment. Only as an approximation, therefore, may one say 
that the probability of F^ representing a given 6p is 1 in 5. 



REF ID:A64644 

- 106 - 

RULE IV. - In thG equation 1*2^ = 3*4(.5 if 2 and 3 
are identical, the letters are all in the same row or 
column, and in the rolative order 124. In the square 
shown, - NKg and the absolute order is ANK. The 
relative order 124 includes five absolute orders .which 
are cyclic permutations of one another. Thus j ANK — , 

NK— A, K— AN, —ANK, and -A1\"K-. 

RULE V. - In the equation 1.2^ ^ 3.4^., if 1 
and 4 are identical, the letters are all in the same row 
or column, and in the relative order 243. In the square 
shovm, KNp - RK^ and the absolute order is NKR. The rela- 
tive order 243 includes five absolute orders v^hich are 
cyclic permutations of one another. Thus NKR — , KR — N, 

R— NK, —NKR, and -NKR-. 

RULE VI. - "Analyze the message for group re- 
currences. Select the groups of g’^eatest recurrence and 
assume them to be high-frequency digraphs. Substitute 
the assijmed digraphs throughout the message, testing the 
assumptions in their relation to other groups of the cipher. 

The reconstruction of "the square proceeds simultaneously 
with the solution of the message and aids in hastening 
the translation of the cipher." 

d. (l) ’.Vhen solutions for the Playfair cipher system were 

first developed, based upon tho fact that the letters were inserted in. 
the cells in keyword-mixed order, cryptographers thought it desirable 
to place stumbling blocks in the path of such solution by departing from 
strict, keyivord -mixed order. Playfair squares of the latter typo are 
designed as "modified Playfair squares". One of the simplest methods is 
illustrated in Fig. 25, wherein it will be noted that the last five 
letters^ of the keyword proper are inserted in tho fourth row of the square 
instead of the second, v/here they would naturally fall. Another method 
is to insert tho letters within tho cells from left to right and top down- 
ward but use a sequence that is a keyword-raixod soquonco developed by a 
columnar transposition based upon the keyword proper. Thus, using the 
keyword BAIVKRUPTCY; 

215479683 10 
. .BANKRUPTCY 
DEFGHILMOQ 
5 V W X Z 



Sequence: ASVBDSCOKGXNF’VPLRHZTMUIYQ 



REF ID:A64644 







- 107 - 



Playfair Square 



lO 


0 


0 


0 


El 


m 


m 


0 


B 


m 


Q 


0 


0 


0 


€ 


ipi 


m 


o 


B 


m 


[iM 


0 


fi 


B 


d 



Pig» 25 b 

(2) In the foregoing square practically all indi- 
cations that the square has been developed from a key- 
word have disappeared. The principal disadvantage of 
such an arrangement is that it requires more time to 
locate the letters desired,- both in cryptographing and 
decryptographing, than it usually does when a semblance 
of normal alphabetic order is preserved in the square. 



(3) Note the following three squares: 




^t first glance they all appear to be different, but 
closer examination shows them to be cyclic permutations 
of one another and of the square in Fig, 25 b. They 
-yield identical equivalents in all cases. However, if 
an attempt be made to reconstruct the original keyword, 
it would be much easier to d» so from Fig. 25 b than 
from any of the others, because in Fig. 25 b the keyv/ord- 
mixed sequence has not been disturbed as much as in 
Figs. 25 c, e. In working v/ith Playfair ciphers, the 
student should be on the lookout for such instances of 
Cyclic permutation of the original Playfair square, for 
during the course of solution he will not knov/ whether 
he is building up the original or an equivalent, cyclic 
permutation of the original square? only after he has 
completely reconstructed the square will he be able to 
determine this point. 

e. (1) The steps in the solution of a typical example 

of this cipher may be useful. Let the message be as follows; 



REF ID:A64644 



- 108 - 

12345 6789X) 311213 14 15 B 1738 19 20 a 22 23 21 25 25 27 28 29 39 

» a • 

A. VTQEU HIOFT GH X S C A K TV T RAZEV TAGAE 

B. OXTYM HGRLZ ZTQTD'.UM’GYC XCTGM TYCZU 

C. SNOPO GXV X S C A K T V. PU T2PTW ZFNBG 

D. PTRKX IXBPR ZOEPU TOLZB KTTCS NHCQM 

E. VTRKM WCFZU BHT7Y ABSIP RZKPC QFNLV 

F. 0 X 0 T U Z FACX XGPZX H GYNO TYOLG XXIIH 

G. T M S M X CPTOT CX OTT-CYATE XH FAG XXGPZ 

2LJi yct xwlzt sgpzt yyv/ge twgcc mbhmq 

J. Y X Z P W G R T I V." , U X P u M ' p 'R K M Vl" G X T M R S W G H B 

K* X G P T 0 T G X' o'T' iM I P Y D fc- G K,l! •T'C'0,L X U E T P X 

L. XFSRS U'ZTDB! .HOZIG' jc’R K I X ‘ZPPVZ IDUHQ 

M. OTKTK GCH X. X 

(2) V/ithout going through the preliminary tests in de- 
tail, with which it will be assumed that the student is now familiar, ^ 
the conclusion is reached that the cryptogram is digraphic in nature, 
and an ordinary, simple digraphic frequency distribution is made. 




REF ID : A64644 






REF ID:A64644 



- 110 - 

Since there are no double-letter groups, the conclusion is reached that 
a Playfair cipher is involved and the message is rev,rritten in digraphs. 





1 


2 


3 


4 


5 


6 


7 


8 


9 


10 


11 


12 


13 


14 


15 


A. 


VT 


QE 


UK 


10 


FT 


CH 


XS 


GA 


KT 


VT 


RA 


ZE 


VT 


AG 


AE 


B. 


OX 


TY 


MH 


CR 


LZ 


ZT 


QT 


DU 


MG 


YG 


XC 


TG 


MT 


YG 


ZU 


C. 


SN 


OP 


DC 


XV 


XS 


CA 


KT 


VT 


PK 


PU 


TZ 


FT 


m 


FN 


PG 


D. 


FT 


RK 


XI 


XB 


PR 


ZO 


EP 


UT 


OL 


ZE 


KT 


TC 


SN 


HC 


QM 


E. 


VT 


RK 




GF 


ZU 


BH 


TV 


YA 


BG 


IP 


RZ 


KP 


CQ 


FN 


LV 


F. 


OX 


OT 


U2 


FA 


CX 


XC 


-PS- 


XH 


GY 


NO 


TY 


CL 


GX 


XI 


IH 


Ct« 


TM 


5M 


'XG 


PT 


OT 


CX 


QT 


TC 


YA 


TE 


XH 


FA 


CX 


XC 


PZ 


H. 


XH 


YC 


TX 


WL 


ZT 


SG 


PZ 


TV 


_Yiir 


CE 


TW 


GC 


CM 


BH 


MQ 


J. 


YX 


ZP 


WG 


RT 


IV 


UX 


PU 


MQ 


RK 


m 


CX 


TM 


RS 


¥G 


HB 


K. 


XC 


PT 


OT 


GX 


OT 


MI 


PY 


DN 


FG 


KI 


TC 


OL 


XU 


ET 


PX 


L, 


XF 


SR 


SU 


2T 


DB 


HO 


ZI 


GX 


RK 


IX 


ZP 


PV 


ZI 


DU 


HQ 


M. 


OT 


KT 


KC 


OH 


XX 























(3) The following three fairly lengthy repetitions 

are noted: 

Lines 



F: 


OT 


UZ 


FA 


CX 


XC 


PZ 


XH 


CY NO 


G: 


TE 


XH 


FA 


CX 


XC 


PZ 


XH 


YC TX 


















-KT- 


At 


FT 


CH 


XS 


CA 


KT 


VT 


RA 


ZB 


C; 


DG 


XV 


XS 


CA 


KT 


VT 


PK 


PU 


G: 


TM 


SM 


XC 


FT 


OT 


CX 


OT 


TG 


K: 


¥G 


HB 


XC 


FT 


CT 


CX 


OT 


MI 



The first long repetition, with the sequent reversed digraphs CX and XC 
immediately suggests the word BATTALION, split up into -B AT TA LI ON 



REF ID : A64644 



^ ' w * t ■** ' "* 

and the sequonco containing this repetition in lines F and G becomes 
as follows t 

w -1 . * 



Line 


F: 


OX 


OT 


UZ 


FA 


cx 


XC 


PZ 


XH 


cy; 


NO 


TE 












B 


AT 


TA 


LI 


ON 




• 




Line 


G: 


YA 


TE 


XH 


sT* 


CX 


XC 


PZ 


15T 


YC 


TX 


’VL 










ON 


B 


AT 


TA 


LI 


ON 









(4) Because of the frequent use of numerals before the 
word BATTALION and because of the appearance of ON before this word in 
line G, the possibility suggests itself that the word before BATTALION 
in line G is either ONE or SECOND. The identical digraph FA ;Ln both 
cases gives a hint that the word BATTALION in line F may also be pre- 
ceded by a numeral; if ONE is correct in line G, then THREE is possible 
in line F. On the other hand, if SECOND is correct in line G, then 
THIRD’ is possible in line F. Thus: 



Line F* 


OX 


OT 


UZ 


FA 


’CX 


XC 


PZ 


XH 


CY 


NO 


TE 


1st hypothesis 




TH 


RE 


EB 


AT 


TA 


LI 


ON 








2nd hypothesis 


— 


TH 


IR 


DB 
















Line G* 


YA 


TE 


XH 


FA 


CX 


XC 


PZ 




YC 


TX 


WL, 


1st hypothesis 


..J 


— 


ON 


EB 


AT 


TA 


LI 


ON 








2nd hypothesis 


-S 


EC 


ON 


DB 

















First, note that if either hypothesis is true,- then OT^ - THp. The 
frequency distribution shows that OT occurs 6 times and is in fact the 
most frequent digraph in the message. Moreover, by Rule I of subpara- 
graph b, if CTj, - TH^ then TO^ - HT . Since HTp is a very rare digraph 
in normal plain text, TO^, should either not occur at all in so short a 
message or else it should be very infrequent. The frequency distribu- 
tion shows its entire absence. Hence, there is nothing inconsistent 
with the possibility that the v/ord in front of BATTALION in lino F is 
THREE or THIRD, and some evidence that it is actually one or the other. 

(5) But can evidence be found for the support of one 
hypothesis against the other? Let the frequency distribution bo examined 
with a view to throwing light upon this point. If the first hypothesis 
is true, then UZ - REp, and, by Rule I, z ®Rp* The frequency dis- 
tribution shows out one occurrence of UZ^ and but xwo occurrences of ZU^. 
These do not look very good for-RB and ER. On the othor hand, if the 
2nd hypothesis is true, then UZ^ s IRp and, by Rule I, ZU^. - Rip. The 
frequencies are much more favorable in this case. Is there anything 
inconsistent v/ith the assumption, on the basis of the 2nd hypothesis, 
that TE^ - ®^p^ The frequency distribution shows no inconsistency, f'»r 
TEq occurs-once and ET^, (= C'Ep, by Rule l) occurs once. As regards 
whether FA^ - EBp or DBp, both hypotheses are tenable; possibly the 
2nd hypothesis is a shade better than the 1st, on the following reasoning. 



REF ID : A64644 



- 112 - 

By Rule I, if FA^ _ EBp then AF^. - BEp, er if FA^ - DBp then AF^ m BDp. 
The fact that nn AF^. occurs, whereas at least one BEp may be expected 
in this message, in'^lines one to the 2nd hypothesis, since BDp is very 
rare. ‘ ' “ 



(d) Let the 2nd hypothesis be assumed to be correct. 

The additional values ai'e ‘tentatively inserted in the text, and in lines 
Gr and K two interesting repetitions are noted: 



Line 


G: 


TM 


SM 


XC 


PT 


or 


cx 


OT 


TO 


YA 


TE 


XH 


FA 


OX 


XC 


PZ 


XH 










TA 




TH 


AT 


TH 




-S 


EC 


ON 


DB 


AT 


TA 


LI 


ON 


Line 


Ks’ 


WG 


HB 


x“ 


FT 


or 


CX 




MI 


PY 


DN 


FG 


KI 


TG 


OL 


XU 


ET 



TA TK AT TH 



This certainly looks like STATE THAT THE ..., which would make TEp s 
Furthermore, in line G the sequence STATETHATTHE. .SECONDB ATT ALIGN can 
hardly be anything else than STATE THAT THEIR SECOND BATTALION, which 
would make TC^, - EIp a“rid YA^,” "a BSp. 'Also SM^ ^ -Sp. 

(7) It is perhaps high time that the whole list of tenta- 
tive equivalent values be studied in relation to their consistency with 
the positions of -letters' in the Playfair square; moreover, by so doing, 
additional values may be obtained in the process. The complete list of 
values is as fellows; 

Assumed values Derived by Rule I 



ATp 


— 


cx„ 


TAp 


H 


XC, 




= 


PZ„ . 




S 


ZPc 


ONp 


- 


®c 


NOp 


— 


HX, 


THp 


— 


OTc' 


HTp 


= 


TO, 




= 


UZc 


Rip 


B 


Zll, 


DBp 




FA, 


BDp 


= 


AF, 


ECp 


= 


TE, 


CEp 


B 


ET, 


TEp 


= 


^^c 


ETp 


= 


T?c 


EIp 


= 


TC, 


lEp 


- 


CT, 


HSp 


= 


I-c 


SRp 


- 


AYc, 




a 


SMc 




B 


MS, 



4 



REF ID : A64644 



- 113 - 



(s) By Rule V, the equation THp - OT^ means that H, T, 
and 0 are all in the same row or column and in xhe relative order 243j 
similarly, C, JS, and T are in the samo row or column and in the relative 
order 243»,^ Further £, P, and T are in the same row, and column; and their 
rotative* order is also 243. That is, thoso sequences must occur in the 
square: 



( 1 ) 

H T 0 . . 

T 0 . . H 

0 . , H T 

i H T 0 

H T 0 






(9) 





(2) 






(3) 






or 


GET., 


9 


or 


E T P . . 


9 


or 


or 


E T . . G 


9 


or 


T P . . E 


9 


or 


or 


T . . G E 


9 


or 


P . . E T 


9 


or 


.•r 


..get 


9 


or 


. •. E T P 


9 


or 




. C'E’T . 






.;*E T P . 






Not ing 


the common 


letters 


E and T in the 


second and 



third sets of relative orders, these may be combined into one sequence 
of four letters. Only one position remains to be filled and noting, in 
the list of equivalents that EIp - TC^, it is obvious that the letter 
I belongs to the GET sequence. The complete soquonce is therefore as 
follows : 



• • - C E T P I , or 

E T P I C , or 
T P I C E , or 
: P I G E T , or 

I G B T P 

(lO) Taking up the HTO sequence, it is noted, in the 
list of equivalents that ONp ~ an equation containing two of the 

throp letters of the HTO sequence. From this it follows that N and X 
must belong to the samo row or column as HTO. Tho ^arrangement must be 
one of thq following: 

- . ■ 1 , . H T 0 X N 

T 0 X N H 
0 X N H T 
X N H T 0 
N H T 0 X 

' ■ ■ (ll) Since tho sequence containing ,HTOXN has a common 

lottor (T) with tho soquonce GETPI, it follows that if tho HTOXN soquonce 
occupies a row, then the GETPI sequence must occupy a column; or, if 
the HTO sequence occupies a column, then the GETPI sequence must occupy 
a row; and they may be combined by means of their common letter, T. 

Simple calculation will show that the two sequences may be combined in 
50 different ways, all of them yielding identical sets of equivalents. 




(12) Before trying to discover means whereby the actual 
rr absolute arrangement may be detected from among the full set of 50 
possible arrangements, the question may be raised: is it necessary? 

Since any one of the 50 arrangements will yield the same equivalents as 
any of the remaining 49, perhaps a relative arrangement will do. 



(13) Let arrangement 13 be arbitrarily selected for trial. 














REF ID : A64644 



- 115 - 

K. 







p 










I 










c 










E 






r 




T 







(14) What additional letters can bo inserted, using as 
a guide the list of equivalents in subparagraph ( 7 )? There is ATp - CX^, 
for example. It contains only one letter, A, not in the arrangement 
selected for trial, and this letter may immediately be placed, as shown: 







P 


□ 








I 










C 




A 






E 






N 


H 


T. 




JL 



Scanning the list for additional cases of this typo, none are found. But 
seeing that several high-frequency letters have already boon inserted 
in the square, perhaps reference to the cryptogram itself in connection 
with values derived from these inserted letters may yield further clues. 
For example, the vowels A, E, I, and 0 are all in position, as aro the 
very frequent consonants N and T. The following combinations may bo 



studied: 

ANp = 


?Xc 


ATp 


' eXc 


NAp 


s X? 


TAp « XCc 


• II 


?Tc 


ETp 


= TPe 


NEp 


= T? 


TEp = PTc 


lEp = 




ITp 


= GPo 


Nip 


r T? 


Tip = PCc 


II 

p. 

0 


XHc 


OTp 


= XOc 


NOp 


= HXc 


TOp = OXc 


ATp (= eXc), 


TAp 


(» XCj, ONp (= XHc), 


TEp 


(» ^0) 


and ETp (= T 



already been inserted in the text. Of the others, only OX^. TOp) 
occurs two times, and this value can bo at once inserted in the text. 
But can the equivalents of AN, El'l, or IN bo found from frequency con- 
siderations? Take ENp, for example; it is represented by ?T . What 
combination of ?T is most likely to represent EN^ among the follov/’ing 
candidates: 



KTj, (4 times); by Rule I, 
VTc (5 times); *' ” ” 
ZTg (3 times); ” '' " 



NB„ would s TK_ (no occurrences) 

P 

NEp ” r TVg (2 times) 

NEp " « TZe (1 time) 







f'--' 





REF ID:A64644 

- 116 - 



VTq cortainly looks good* it begins tho message, suggesting the word 
EN5MY; in line H, in tho sequence PZTV would become LINE. Lot this be 
assumed to bo correct, ani lot tho word ENEMY also be ass'jmed to be 
correct. Then EMp z and the square then becomes as shown herewith* 







P 










I 










C 




A 


V 


M 


E 






N 


H 


T 


0 


X 



(15) In line E is seen the follov/ing sequence: 

Lino E* VT RK MW RF ZU BH TV Y.^ BG IP RZ KP CQ FN LV 

EN RI NE RS PT E 

Tho sequence RI..NBRS..PT suggests HIISONERS CAPTURED, as follows* 

m GF ZU PH TV YA BG IP RZ KP 

P RI SO NE RS Ca PT UR ED 

This gives the following now values* -P s CF ; SO = BH^; CA z BG^,} 
URp.= RZc5 EDp “ KPc. 

Tho letters B and G can bo placed in position at once, since tho posi- 
tions of C and a are already known. The insertion of tho letter B im- 
mediately permits the placement of tho letter S, from the equation 
SOp - BH^. Of the remaining equations only EDp s KP„ can bo used. Since 

E and P are fixed, and are in the same column, D and K must be in the 
same column, and moreover the K must be in tho same row as E. There 
is only one possible position for K, viz., iramediatoly after Q. This 
automatically fixes the position of D. The square is now as shown here- 
with* 







p 




D 






I 






G 


5 


c 


B 


A 


V 


M 


E 


s. 


K 


F 




T 


0 


X 



(16) A review of all equations, including tho very first 
ones established, gives the following which may now be used; DBp 3 
BSp _ YAq. Tho first permits tho immediate placement of Fj the second, 
by elimination of possible pcsitions, permits the placement of both R 
and Y, The square is now as sho-jim herewith* 





REF ID : A64644 



- 117 - 







P 


F 


D 




Y 


I 




R 


G 


S 


C 




A 


V 


M 


E 


fi. 


K 


N 


H 


T 




X. 



Onc§ moro a reviev; is made of all remaining thus far unused equations* 
Lip - PZg nov/ permits the placement of L and Z* IRp s UZ^. now pomits 
the placement of U, which is confirmed by the equation UR_ ~ RZ^, from 
the word C-iPTURED. 



L 




P 


F 


D 


Z 


Y 


I 


U 


R 


G 


5 


F 


hb" 


A 


V 


ir 


IE 


w 


T 


dtL 


H. 


3 




Xi 



There is thon only one cell vacant, and it must bo occupied by the only 
letter loft unplaced, viz., W. Thus the whole square has been recon- 
structed, and the message can now be decryptographed. 



(17) Is the square just reconstructed identical with 
the original, or is it a cyclic permutation of a keyword-mixed Playfair 
square of tho typo illustrated in Fig. 25b? 'Even though the message 
can be read with ease, this point is still of interest. Let the sequence 
bo written in five ways, each composed of five partial sequences made 
by cyclicly permuting each of the horizontal rows of the reconstructed 
square. Thus; 







Row 


1 




Rov/ 


2 






Rew 


3 






Raw 


(a) 


L 


W 


P 


F D 


Z 


Y 


I 


U 


R 


G 


S 


C 


B 


A 


V 


M £ 


,(b) 


W 


P 


F 


D L 


Y 


I 


U 


R 


Z 


S 


C 


B 


A 


G 


U 


E Q 


(c) 


P 


F 


D 


L W 


I 


U 


R 


2 


Y 


C 


B 


A 


G 


S 


E 


q K 


'id) 

‘J 


F 

• 


D 


L 


W P 


U 


R 


Z 


Y 


I 


B 


A 


G 


S 


C 


Q 


K V 


Co) 


D 


L W 


P F 


R 


Z 


Y 


I 


U 


■a 


G 


S 


C 


B 


K 


V M 



4 

Q K 
K V 
V M 
M E 
E Q 



Row 5 
N H T 0 X 
H T 0 X N 
T 0 X N H 
0 X N H T 
X N H T 0 



By experimenting with those five sequences, in an endeavor to reconstruct 
a transposition rectangle conformable to a keyvrord sequence, tho last 
sequence yields tho following; 

P Y A C M N 
D F I G B B H 
L R U S K Q T 
V/ Z V X 0 





REF ID:A64644 

- 118 - 

By shifting tho 0 from tho last position to tho first, and rearranging 
tho columns, tho following is ohtainod* 

2 5 3 6 1 4: 7 
C 0 M P N Y 
B D £ F G H I 
K L q R S T U 
V W X Z 

Tho original square must hjivo been this: 



A 


G 


s 


n 

\j 


B 


K 


V 


M 


E 


Q-4 


"xl 


In 


H 


T 


0 


D 


L 


v; 


P 


F 


R 


z 


Y 


I 


U 



f . Continued practice in the solution of Playfair ciphers v/ill 
make tho student quite export in the matter and will enable him to solve 
shorter and shorter messages, jilso, with practice it v/ill become a mat- 
ter of indifference to him as to whether the letters are inserted in the 
square with any sort of regularity, such as simple k'eyv/ord -mixed order, 
columnar transposed keyv/ord-mixed order, or in a purely random order. 

g. . It may perhaps seem to tho student that tho foregoing steps 
are somewhat tco artificial, a bit too "cut and dried" in their accuracy 
to portray the process of analysis, as it is applied in actuality. For 
example, the critical student may well object to some of the assumptions 
and the reasoning in stop (s) above, in which tho words THREE and ONE 
(1st hypothesis) were rejected in favor of tho words THIRD and SECON’D 
(2nd hypothesis). This rested largely upon the rejection o’f RE a'nd ERp 
as the equivalents of and ZU^, ojid tho adoption of IR^ and Rip as 
their equivalents. Indeed, if the student will oxamino the final message 
with a critical eye ho will find that while the bit of reasoning in step 
(5) is perfectly logical, tho assumption upon which it is based is in 
fact wrong, for it happens that in this case ER^ occurs only once and 
REp does not occur at all. Consequently, although most of the reasoning 
which led to the rejection of tho 1st ‘hypothesis and the adoption of tho 
2nd was logical, it was in fact based upon erroneous assumption. In 
other words, despite the fact that tho assumption was incorrect, a correct 
deduction v/as made. The student should take note that in cryptanalysis 
situations of this sort ar.o not at all unusual . Indeed they are to be 
expected and a few words of explanation at this point may bo useful. 

h. Cryptanalysis is a science in which a very large role is played 
by making deductions from observational da-ba and the deductions usually 
rest upon assumptions. It is most often the case that tho cryptanalyst 
is forced to make his assumptions upon a quite limited amount of text. 



REF ID:A64644 



- 119 - 

It cannot be oxpectod that assumptions basod upon statistical generali- 
zations wili alv/ays hold truo when applied to data comparatively very 
much smallor in quantity than tho total data used to derive the genera- 
lized rules. Consoquontlyj as regards assumptions mado.in specific 
raossdges, most of tho time thoy will bo correct, but occasionally they 
v/ill bo incorrect. In cryptanalysis it is often found that among the 
correct deductions there v/ill bo cases in which subsequently discovered 
facts do not boar out the assumptions on which tho deduction was basod. 
Indeed, it is sometimes truo that if tho facts had boon known before tho 
deduction was made, this knov/lodgo would havo provontod making tho cor- 
rect deduction. For ex?.mplo, suppose tho cryptanalyst had somehow or 
other devinod that tho message under consideration contained no RE, only 
one 3R, one IR, and two RI's (as is actually tho case). Ho would certainly 
not havo boon able to choose between the v/ords THREE and ONE (1st hypothe- 
sis) as against THIRD and SECOND (2nd hypothesis). But because he assumes 
that there should bo raoro’ERp's and-REp‘s than IR's-and RI's in tho message, 
he deduces that UZ^ cannot be HBp, rejects the 1st hypothesis and takes 
the 2nd. 'It later turns out, after tho problem has been solved, that the 
deduction 'was 'correct, although tho assumption on which it was basod 
((^xpoctation of more frequent appearance of RBp and BRp) was not in fact 
true in this particular case. The cryptanalyst can only hope that tho 
number of'tlmes when his deductions are correct, even though based upon 
a"Ssumptions which later turn out to bo orronoous, will abundantly exceed 
thp numbor of times when his deductions are v/rong, oven though based upon 
assumptions which later prove t» be correct. If ho is lucky, the making 
of an assumption which is really not truo v/ill make no difference in tho 
end and will not delay solution; but if ho is specially favored with luck, 
it may actually help him solve the message — as was tho case in this parti- 
cular example. 

i. imothor comment »f a general nature may bo mode in connection 
with this specific example. The student may ask what would havo been tho 
procedure in this case if the message had not' contained such a tell-tale 
repetition as the v/ord B-»TT.iLION, which formed tho point of departure for 
tho solution, or, as it is often said, permitted an "entoring v/odge" to 
bo driven into tho message. Tho answer to his query is that if tho word 
BATTALION had not boon repeated, there would probably havo been some other 
repetition which would havo permitted tho same sort of attack. If tho 
studohi is looking for cut and dried, straightforward, unvarying methods 
of attack, ho should remember that cryptanalysis, while it may bo considered 
a branch of mathematics, is not a science which has many "general solu- 
"tfons" such as are found and expected in mathematics proper. It is in- 
herent in the very nature of cryptamlytics that , os, a rule , only gonoral 
principles can bo established; their practical application must take ad- 
vantage of peculiarities and particular situations v/hich are noted in 
'"specific messages. This is especially truo in a text on tho subject. 

The illustration of a gonoral principle requires a specific example, and 
the latter must of necessity manifest characteristics which make it differ- 
ent from any other oxampld. The’ word BATTiiLION was riot purposely repeated 



REF ID:A64644' 

- 120 - 



in this example in order to make the demonstration of solution easy; 

"it just happened that way". In another example, some other entering 
wedge would have been found. The student can be expected to learn only 
the general principles which will enable him to take advantage of the 
specific characteristics manifested in specific cases . Here it is de- 
sired to illustrate the general principles of solving Playfair ciphers 
and to point out the fact that entering wedges must and can be found. 

The specific nature of the entering wedge varies with specific examples. 

SECTION X 

CONCLUDING REMARKS ' 

# 

Paragraph 



Special remarks concerning the initial classification of 

cryptograms 47 

Ciphers employing characters other than letters or figures ... 48 

Concluding remarks concerning monoalphabet ic substitution. ... 49 

Analytical key for cryptanalysis 50 



47. Special remarks concerning the initial classification of cryp- 
tograms. - a. The student should by this time have a good conception of 
the basic nature of monoalphabet ic substitution and of the many "changes" 
which may be "rung" upon this simple "tune". The first step of all, 

naturally, is to be able to classify a cryptogram properly and place it 

in either the transposition or the substitution class. The tests for 
this classification have been given and as a rule he will encounter no 
difficulty in this respect. 

b. There are, however, certain kinds of cryptograms whose class 

cannot be determined in the usual manner, as ou.tlined in Par. 13 of this 
text. First of all there is the type of code message which employs bona 
fide dictionary words as code groups.^ Naturally, a frequency distribu- 
tion of such a- message will approximate that for normal plain text. The 
appearance of the message, however, gives clear indications of what is 
involved. The study of such cases will be taken up in its proper place. 
At the moment it is only necessary to point out that these are code 

messages and not cipher , and it is for this reason that in Pars. 12 and 

13 the words "cipher" and "cipher messages" are used, the v/ord "crypto- 
gram" being used only where technically correct. 

c. Secondly, there come the unusual and borderline cases, including 
cryptograms whose nature and type can not -be ascertained from frequency 
distributions. Here, the cryptograms are technically not ciphers but 
special forms of disguised secret writings v/hich are rarely susceptible 
of being classed as transposition or substitution. These include a large 
share of the cases wherein the cryptographic messages are disguised and 
carried under an external, innocuous text v/hich is innocent and seemingly 

^ See Par. 71, Special Text No. 165, Elementary Military Cryptography. 



REF ID:A64644 







withcut cryptographic contant - for instance, in a message wherein specific 
letters are indicated in a way not open to suspicion under censorship, 
these letters being intended to constitute the letters of the cryptographic 
message and the other letters constituting “dummies"* Obviously, no amount 
of frequency tabulations will avail a competent, expert- cryptanalyst in 
demonstrating or disclosing the presence of a cryptographic message, 
written and secreted within the “open** message, which serves but as an 
envelop and disguise for its authentic or real import. Certainly, su#h 
frequency tabulations can disclose the existence neither of substitution 
nor transposition in those cases, since both forms are absent. Another 
very popular method that resembles the method mentioned above has for its 
basis a simple grille*. The whole v/ords forming the secret text are in- 
serted vri-thin perforations cut in the paper and the remaining space filled 
carefully, using "nulls*' and "dummies", making a seemingly innocuous , 
ordinary message. There are other methods of this general type which can 
obviously neither be detected nor cryptanalyzed , using the principles of 
frequency of recurrences and repetition. These can not be further dis- 



cussed herein, 
their handling. 



but at a subsequent date a special text may be written for 



I 



d. In view of the foregoing remarks, when so-called "symbol ciphers", 
that is, ciphers employing peculiar symbols, signs of punctuation, diacriti- 
cal marks, figures of "dancing men", and so on are encountered in practi- 
cal work nowadays, they are almost certain to be simple, monoalphabet io 
ciphers. They are adequately described in romantic tales, in popular 
books on cryptography, and in the more common types of magazine articles. 

No further space need be given ciphers of this type in this text, not only 
because of their simplicity but also because they are encountered in mili- 
tary cryptography only in sporadic instances in censorship activities. 

Sven in the latter cases, it is usually found that such ciphers are em- 
ployed in "intimate" correspondence for the exchange of sentiments that 
appear less decorous when set forth in plain language. They are very 
seldom or never used by authentic enemy agents. When such a cipher is 
encountered novradays it may practically alv/ays be regarded as the work of 
the veriest tyro, when it is not that of a "crank" or a mentally deranged 
person. 



e. The usual preliminary procedure in handling such cases, where 
the symbols may be somewhat confusing to the mind because of their un- 
familiar appearance to the eye, is to substitute letters for them con- 
sistently throughout the message and then treat the resulting text as an 
ordinary cryptogram composed of letters is treated. This procedure also 
facilitates the construction of the necessary frequency distributions, 
yrhich would be tedious to construct by using symbols. 

^ The subparagraph which the student has just read (4-7£) contains a hidden 
cryptographic message. With the hints given in Par. 35e let the student 
Bee if he can find it. 

^ The most famouss Poe's "Gold Bug"; ■‘Arthur Conan Doyle's "The Sign of 
Four". 



REF ID : A64644 



- 122 - 

f . A final word must be said on tho subject of symbol ciphers by 
way of caution* Wlien symbols are used to replace letters, syllables and 
entire v/ords, then the systems approach code methods in principle, and 
can become difficult of solution.^ The logical oxtonsion of tho use of 
S 3 mibols in such a form of 'writing is tho employment of arbitrary charactors 
for a specially developed "shorthand" system bearing little or no resem- 
blance to woll-knovm, and therefore nonsocrot, systems of shorthand, such 
as "Gregg", "Pitman", etc. Unless a considerable amount of text is avail- 
able for analysis, a privatoly-do vised shorthand may bo very difficult if 
not impossible to solve. Fortunately, such systems are never encountered 
in military cryptography. They fall under the heading of cryptographic 
curiosities, of interest to tho crypto.nalyst in his leisure moments. 2 

48. Ciphers employing characters other than letters or figures. - a. 

In practical cryptography today, tho use of charactors other than tho 26 
letters of tho English alphabet is comparatively raro. It is true that 
there are a few governments which still adhere to systems yielding cryp- 
tograms in groups of figures. These are almost in every case code systems 
and './ill bo treated in their proper place. In some cases cipher systems, 
or systems of onciphoring code aro used v/hich are basically mathematical 
in character and operation, and therefore use numbers instoa.d of letters. 

Some persons aro inclined toward tho use of numbers rather than letters 
because numbers lend thomsolvos much more readily to certain arithmetical 
operations such as addition, subtraction, and so on, than do letters. But 
there is usually added some final process whereby tho figure groups are 
converted into letter groups, for tho sake of economy in transmission. 

b. Tho only nota.blo exceptions to tho statement contained in the 
first sentence of this paragraph aro those of Russian mossagos transmitted 
in tho Russian Morse alphabet and Japanese messages, transmitted in tho 
Kata Ka.na Morse alphabet. 

49. Concluding remarks concorning monoalphabet ic substitution. - a. 

Tho alert student v/ill have by this timo gathered that tho solution of 
monoalphabetic substitution ciphers of tho simple or fixed typo aro particu- 
larly easy to solve, once the underlying principles aro thoroughly under- 
stood. As in other arts, continued practice with examples loads to facility 
and skill in solution, especially whore the student concentrates his atten- 
tion upon traffic all of tho same general nature, so tho.t tho typo of text 

^ Tho use of symbols for abbreviation and speed in v^rriting goes back to 
the days of antiquity. Cicoro is reported to have drawn up "a book like 
a dictionary, in which ho placed before each v/ord the notation (symbol) 
v/hich should represent it, and so groat was tho number of notations and 
words that whatever could bo written in Latin could bo expressed in his 
notations . " 

2 An example is found in tho famous Popys Diary, which was v/ritton in 
shorthand, purely for his ov/n eyes by Samuel Popys (1633-1703). "Ho wrote 
it in Shelton's system of tachygraphy (1641), which ho complicated by using 
foreign languages or by variotios of his own invention whonovor he had to 
record passages least fit to bo soon by his servants, or by 'all tho world'." 



REF ID : A64644 

- 123 - 

which ho is continually oncountoring bocomos familiar to him and its 
poculiaritioB or charactoristics of construction givo duos for short 
cuts to solution. It is truo that a knowlodgo of tho gonoral phraseology 
of mo^Sago^,' tho kind of words used, thoir soquoncos, and so on is of very 
great assistanco in practical work in all fields of cryptanalysis. The 
student is urged to note particularly those finer details in the course 
of his study. 

b. Another thing which the student should be on the lookout for in 

' simple monoalphabetic substitution is the use, consecutively of several 

different mixed cipher alphabets in a single long message. Obviously, a 
single, composite frequency distribution for the whole message will not 
show the clmracteristic crest and trough appearance of a simple monoalpha- 
betic cipher, since a given cipher letter will represent different plain- 
text letters in different parts of the message. But if the cryptanalyst 
will carefully observe the distribution as it is being compiled, he will 
note that at first it presents the characteristic crest and trough appear- 
ance of monoalphabeticity , and that after a time it begins to lose this 
aj^pearance. If possible he should be on the lookout for some peculiarity 
of grouping of letters which serves as an indicator for the shift from 
one cipher alphabet to the next. If he finds such an indicator he should 
begin a second distribution f rom that point on, and proceed until another 
shift or indicator is encountered. By thus isolating the different portions 
of the text, and rostricting the frequency distributions to the separate 
monoalphabets, the problem may be treated then as an ordinary simple mono- 
alphabetic substitution. 

c. Monoalphabetic substitution with variants represents an extension 

• of the basic principle, with the intention of masking the characteristic 

frequencies resulting from a strict monoalphabeticity, by moans of which 
solutions are rather readily obtained. Some of tho subterfugos applied 
in tho establishment of variant or multiple values aro simple and more or 
less fail to servo tho purpose for which they aro intondodj others, on 
tho contrary, may interpose sorious difficulties to a straight forwai’d solu- 
tion. But in no case may tho problem be considered of more than ordinary 
difficulty”. " Furthermore, it should bo recognized that whore these subter- 
fuges aro really adequate to tho purpose, tho complications introduced aro 
such that tho practical manipulation of tho system becomes as difficult 
for the cryptographer as for tho cryptanalyst. 

As already montionod in monoalphabetic substitution with variants 
it is most common to employ figures or groups of figures. The reason for 
this is that tho uso of numerical groups sooms more natural or easier to 
> tho uninitiated than does tho uso of varying combinations of letters. 

Moroovor, it is oasy to draw up cipher alphabets in which some of the let- 
ters are represented by single digits, others by pairs of digits. Thus, 
tho decomposition of tho cipher text which is an irregular intermixture of 
monolitbraT'and polylitoral oquivalonts, is made more complicated and 
correspondingly difficult for tho cryptanalyst, v;ho does not know which 
digits are to bo used separately, which in pairs. 






REF ID:A64644 



- 124 - 

0 . A fow v/ords may bo addod horo in regard to a mothod which often 
suggests itsolf to laymon. This consists in using a book possossod by 
all tho corrospondonts and indicating the lofttors of tho inossago by moans 
of numbers reforrihg to spocific lottors in tho book. One way consists 
in selecting a contain page and then giving tho lino number and position 
of the letter in the lino, tho page number being shown by a single initial 
indicator. Another way is to use tho entire book, giving tho cipher 
equivalents in groups of three numbers representing page, line, and number 
of letter. (iSx.s 75-8-10 means page 75, 8th line, 10th letter in the 
lino.) Such systems aro, however, extremely cumbersome to use and, whon 
tho cryptographing is done carelessly, can bo solved. Tho basis for solu- 
tion in such cases rosts upon tho uso of adjacent lottors on the same lino, 
the accidental repetitions of certain lottors, and tho occurrence of un- 
enciphored words in tho messages, when laziness or fatiguo intervenes in 
tho cryptographing. 

f. It may also be indicated that human nature and tho fallibility 
of cipher clerks is such that it is rather rare for an encipherer to make 
full use of the complement of variants placed at hie disposal. Tho result 
is that in most cases certain of tho oquivalonts will bo usod so much 
more ofton than others that diversities in frequencies will soon manifest 
thomsolves, affording important data’for attack by the cryptanalyst. 

In the World War the cases whore monoalphabetic substitution 
ciphers were employed in actual operations on the Western Front were ex- 
ceedingly rare because the majority of the belligerents had a fair know- 
ledge of cryptography. On the Eastern Front, however, the extensive use, 
by the poorly prepared Russian Army, of monoalphabetic ciphers in the 
fall of 1914 was an important, if not the most important, factor in the 
success of the German operations during the Battle of Tannenberg. It 
seems that a somewhat more secure cipher system was authorized, but proved 
too difficult for the untrained Russian cryptographic and radio personnel. 
Consequently, recourse was had to simple substitution ciphers, somewhat 
interspersed with plain text, and sometimes to messages completely in 
plain language. The damage which this faulty use of cryptography did to 
the Russian Array and thus to the Allied Pov/ers is incalculable. 

h. Many of the messages found by censors in letters sent by mail 
during the World War were cases of monoalphabetic substitution, disguised 
in various ways. 

^ Gyldon, Yvos. Chif forbvr&ornas Insatsor I V&rldskriget Till Lands , 

Stockholm, 1931. Translation under the title Tho Contribution of tho 
Cryptographic Bureaus in the World War , appeared in the Signal Corps 
Bulletin in seven success ivo installments, from November-Doc ember 1933 
to November- Doc embor 1934, inclusive. 

Nikolaieff , A. M. Sec rot Causes of German success on the Eastern Front . 
Coast Artillery Journal, Septerabor-Octobor, 1935. 



REF ID:A64644 



- 125 - 

50. Analytical key for cryptanalysis. - a. It may be of assistance 
to indicate, by means of an outline, the relationships existing among 
the various cryptographic systems thus far considered. This graphic out- 
line will be augmented from time to time as the different cipher systems 
are examined, and will constitute what has already been alluded to in 
Par,. 6 ^ and there termed an analytical key for cryptanalysis .1 Funda- 
mentally its nature is that of a schematic classification of the different 
systems examined. 

b. Note, in the analytical key, the rather clear-out, dichotomous 
method of treatment, that is, classification by subdivision into pairs. 

For example, in the very first step there are only two alternatives: the 

cryptogram is either (l) cipher, or (2) code. If it is cipher, it is 
either (l) substitution (2) transposition. If it is a substitution cipher, 
it is either (l) monographic, or (2) polygraphic, and so on. If the stu- 
dent will study the analytical key attentively, it will assist him in 
fixing in mind the manner in which the various systems covered thus far 
are related to one another, and this will be of benefit in clearing away 
some of the mental fog or haziness from which he is at first apt to suffer. 

^ This analytical key is quite analogous to the analytical keys usually 
found in the handbooks biolcgists commonly employ in the classification and 
identification of living organisms. In fact, there are several peints of 
resemblance between, for example, tl^at branch of biology called taxonomic 
botany and cryptanalysis. In the former the first steps in the classifi- 
catory process are based upon observation of externally quite marked differ- 
ences; 'as the’ process continues, the observational details become finer and 
finer, involving more and more difficulties as the work progresses. Towards 
the end of the work the botanical taxonomist may have to dissect the speci- 
men and study internal characteristics. The wh«le process is largely a 
matter of painstaking, accurate observation of data and drawing proper coi- 
clusions therefrom. Except for the fact that the botanical taxonomist de- 
pends almost entirely upon ocular observation of characteristics while the 
cryptanalyst in addition to observation must use some statistics, the steps 
taken by the former are quite similar to those taken by the latter. It is 
only at the very end of the work that a significant dissimilarity between 
the two sciences arises. If the botanist makes a mistake in observation 
or deduction, he merely fails to identify the specimen correctly; he has an 
"answer" — but the answer is wrong. He may not be cognizant of the error; 
however, other more skillful botanists will find him out. But if the 
cryptanalyst makes a mistake in observation or deduction, ho fails to get 
any "answer" at all; he needs nobody to tell him he has failed. Further, 
there is one additional important point of difference. The botanist is 
studying a bit of Nature -- and she does not consciously Interpose obstacles, 
pitfalls, and' dissimul?.tions in the path of those trying to solve her mys- 
teries. The cryptanalyst , on the other hand, is studying a piece of writing 
prepared with the express purpose of preventing its being read by any per- 
sons for v/Bom it is not intended. The obstacles, pitfalls, and dissimula- 
tions are hero consciously interposed by the one who cryptographed the 
message. These, of course, are what make cryptanalysis different and diffi- 
cult . 



REF ID: A6 4-6 4 4 



« , - 126 - 

c. Tho numbers in pT,ronthescs rofor to specific par^grT-phs in this 
text, so that tho student may raadily turn to tho text for dotailod in- 
formation or for purposes of refreshing his memory as to procedure. 

4.. In addition to those reference numbers thoho have boon affixed 
to the successive stops in the dichotomy, numbers that marie the "rowtos" 
on the cryptanalytic map (tho analytical koy) v/hich the student cryptana- 
lyst should follow if ho v/ishos to facilitate his travels along tho rather 
complicated and difficult road to succoss in cryptanalysis, in somewhat 
tho same way in which ‘an intelligent motorist follov/s the routes indicated 
on a geographical map if ho wishes to facilitate his travels along unfamiliar 
roads. The analogy is only partially valid, however. Tho motorist usually 
knov/s in advance the distant point which ho dosiros to roach and ho proceeds 
thereto by tho best and shortest route, v/hich he finds by observing the 
route indications on s; map and following tho route markers on the road. 
Occasionally ho encounters a detour but those are unexpected difficulties 
as a rule. Least of all doos ho anticipate any necessity for journeys 
down what may soon turn out to bo blind calloys and “dead-end" streets, 
forcing him to double back on his way. Nov tho cryptanalyst also has a 
distant goal in mind — tho solution of tho cryptogram at hand — but he 
does not know at tho outset of his journey the exact spot v/here it is located 
on tho cryptanalytic map. The map contains many routes and ho proceeds to 
tost them one by one, in a successive’ chain. He encounters many blind 
alleys and dead-end streets, which force him to retrace his stops; he makes 
many detours and jumps many hurdles. Some of those rotracings of steps, 
doubling back on his tracks, jumping of hurdles and detours are unavoidable, 
but a few are avoidable. If properly employed, tho analytical koy will 
help the careful student to avoid those which should and can bo avoided; 
if it does that much it will serve tho principal purpose for which it is 
intended. 



e. Tho analytical key may, however, servo another purpose of a some- 
what different nature. liVhon a multitude of cryptographic systems of di- 
verse typos must be filod in some systematic manner apart from tho names 
of the correspondents or other reference da.ta, or if in conducting in- 
structional activities classif icatory designations iiro desirable, tho ref- 
erence numbers on the analytical key may bo made to serve as "type numbers". 
Thus, instead of stating that a given cryptogram is a koyword-syst omat i- 
cally-raixod-monoliteral-monoalphabotic-monographic substitution cipher one 
may say that it is a "Type 901 cryptogram". 

f. Tho method of assigning typo numbers is quite simple. If tho stu- 
dent will examine tho numbers ho will note that successive levels in the 
dichotomy are designated by successive hundreds. Thus, tho first level, 
tho classification into cipher and code is assigned the numbers 101 and 
102. On tho second level, under cipher, tho classification into monographic 
.and polygraphic systems is assigned tho numbers 201 and 202, etc. Numbers 
in the same hundreds apply therefore to systems .at tho same level in the 
classification. There is no particular virtue in this scheme of assigning 
type numbers except that it provides for a considerable degree of expansion 
in future studios. 



REF ID : A64644 



^ 1|C lie 3|< * iK >(• He ^ He ifc >|t * ^ ^ iK 

* * 

I APPENDIX 1 I 

H< * 

* ♦ 

;|c:|c;|c:|c;|c 4::ii)|<H<HeHe’ie>HH:HeHeHe’l<He>ie>l<HeHe’ie!<e>K’|eHe 



REF ID, ^^64 644 

t;:3le i-k 

Absolute froquenoies of letters appearing in five sets of Govern- 
mental plain- text tclegr>-.ms, c_ch set contesining 10,000 letters. 

Arranged alphabetically. 



Message 


Message 


Message 


Message 




;ssage 


No. 1 


No. 2 


No. 3 


No. 4 


No. 5 


S 


^.1 


>> 






I'* 


<0 u 


<D O 
■ ^ 


(D O 


a> u 

>■>1 rt 




® u 

P O 




pj o 


+T M 


Ih 0 q 


u 




ffl H ^ 


® rH P«, 


® <H g. 


(D t-1 0 

t «« o n* 


® 

•P 


o ^ 


vj O' 

+9 03 O 


•4>s* O O' 

•P CQ 0) 


•T^ W W 

■p 03 a> 


02 0) 


P 


® ® 


<D .o (h 


O fO ^ 


<0 ^ u 


® fi ^ 


0 


■s y 


^ PH 


i-p *<1^ 


■«< 1*1 


^ j*) 


I-:* 




A - 738 


A - 78b 


A - 681 


A - 740 


A 


- 741 


B - 104 


B - 103 


B - 93 


3-33 


3 


- 99 


C - ^19 


C - 300 


G - 238 


C - 526 


C 


- 501 


D - 387 


D - 413 


D - 423 


D - 451 


D 


- 448 


E -1367 


E -1294 


E -1292 


E -]270 


E 


-1275 


F - S53 


F - ,287 


F - 308 


F - 287 


F 


- 281 


G - 166 


G - 175 


G - 161 


G - 167 


G 


- 150 


H - 310 


H - 351 


H - 335 


K - 349 


H 


- 349 


I - 742 


I - 750 


I - 737 


I - 700 


I 


- '•97 


J - 18 


J - 17 


J - 10 


J - 21 


J 


- 16 


K - 36 


E - 38 


K - 22 


K - 21 


K 


- 31 


L - 365 


L - 395 


L - 533 


L - 586 


L 


- 344 


M - 242 


M - 240 


M - 238 


M - 249 


M 


- 268 


N - 786 


N - 794 


N - 816 


N - 800 


N 


- 780 


0 - 685 


0 - 770 


0 - 791 


0 - 756 


0 


- 762 


P - 241 


P - 272 


P - 317 


P - 245 


P 


- 260 


Q - 40 


Q - 22 


Q - 45 


Q - 38 


Q 


- 30 


R - 760 


R - 745 


R - 762 


R - 735 


R 


- 736 


S - 658 


S - 503 


S - 585 


S - 628 


S 


- 604' 


T - 936 


T - 879 


T - 894 


T - 958 


T 


- 928 


U - 270 


U - 233 


U - 312 


U - 247 


U 


- 238 


V - 163 


V - 173 


V - 142 


V - 133 


V 


- 155 


W - 166 


W - 163 


w - 136 


n - 133 


V.' 


- 182 


X - 43 


X - 50 


X - 44 


X - 53 


X 


- 41 


i -"191 


Y - 155 


Y - 179 


Y - 213 


Y 


- 229 


Z - 14 


Z - 17 


Z - 2 


Z - . 11 


Z 


- 5 



Tptals 

10,000 10,000 10,000 10,000 10,000 

Table 2-A 



Absolute, frequencies of letters appearing in the combined five sets 
of messages totalling 50,000 letters arr: nged alphabetically. 



A 


- 3683 


G - 


819 


I. 


- 1821 


Q - 


175 


V - 


766 


B 


- 487 


H - 


1694 


M 


- 1237 


R - 


3788 


W - 


780 


C 


- 1534 


I - 


3676 


N 


- 3975 


S - 


3058 


X - 


231 


D 


- 2122 


J - 


82 


0 


- 5764 


T - 


4595 


Y - 


967 


E 

F 


- 6498 

- 1416 


K - 


148 


P 


- 1335 


U - 


1300 


Z - 


49 



REF ID : A64644 

*%*iQ 

TABLE 1-B 



Absolute frequencies of letL&rs appe-iring in five sets of Gov- 
ernment plfin-text telegruas, set containing 10,000 letters. 



Arranged according to frequenc 7 . 



Message 



Message 
No. 2 



Message 
No. 3 



Message 
No. 4 



Message 
No.‘ 5 



u 


0 u 

■e 0 




0 O 
P 0 
^ Q 




ha 
0 u 

^ 1 




hi 

0 0 
13 PS 

fS 0 




hi 

0 0 
13 

p 0 


<0 


iQ p, 


0 


r-l P 


0 


0 




0 


H n 


•P 


O C3CI 


P 


o 


P 


o o' 


P 


o a* 


P 


9 


P 


03 0 


P 


03 0 


P 


03 0 


P 


IQ 0 


P 


9 Q> 


0 




0 


fn 


0 


jq u 


0 


.Q h 


0 


Ih 








hq 


I*) 






yq 




E 


-1367 


E 


-1294 


E 


-1292 


E 


-1270 


E 


-1275 


T 


- 936 


T 


- 879 


T 


- 894 


T 


- 958 


T 


- 928 


N 


- 78'6 


N 


- 794 


N 


- 815 


N 


- 800 


R 


- 786 


R 


- 760 


A 


- 783 


0 


- 791 


0 


- 756 


N 


- 780 


I 


- 74E 


0 


- 770 


I 


- 787 


A 


- 740 


0 


- 762 


A 


- 738 


I 


- 750 


R 


- 762 


R 


- 735 


A 


- 741 


0 


- 685 


R 


- 745 


A 


- 681 


I 


- 700 


I 


- 697 


S 


- 658 


S 


- 583 


S 


- 585 


S 


- 628 


S 


- 604 


D 


- 387 


D 


- 413 


D 


- 423 


D 


- 451 


D 


- 448 


L 


- 365 


L 


- 393 


H 


- 335 


L 


- 386 


H 


- 349 


C 


- 319 


H 


- 351 


L 


- 353 


H 


- 349 


L 


- 344 


H 


- 510 


C 


- 500 


P 


- 317 


C 


- 326 


C 


- 301 


U 


- 270 


F 


- 287 


U 


- 312 


F 


- 287 


F 


- 281 


F 


- 253 


P 


- 272 


F 


- 308 


M 


- 249 


M 


- 268 


M 


- 242 


M 


- '240 


C 


- 288 


U 


- 247 


P 


- 260 


P 


- 241 


U 


- 233 


M 


- 238 


P 


- 245 


U 


- 238 


Y 


- 191 


G 


- 175 


Y 


- 179 


Y 


- 213 


y 


- 229 


G 


- 166 


V 


- 173 


G 


- 161 


G 


- 167 


w 


- 182 


W 


- 166 


W 


- 163 


V 


- 142 


V 


- 133 


Y 


- 155 


V 


- 163 


Y 


- 155 


E 


- 136 


W 


- 133 


G 


- 150 


B 


- 104 


B 


- 103 


B 


- 98 


B 


- 83 


B 


- 99 


X 


- 43 


X 


- 50 


Q 


- 45 


X 


- 53 


X 


- 41 


Q 


- 40 


K 


- 38 


X 


- 44 


Q 


- 38 


K 


- 31 


K 


- 36 


Q 


- 22 


K 


- 22 


K 


- 21 


Q 


- 30 


J 


- 18 


J 


- 17 


J 


- 10 


J 


- 21 


J 


- 16 


Z 


- 14 


Z 


- 17 




- 2 


Z 


- 11 


Z 


- 5 



10,000 10,000 10,000 10,000 10,000 



TABLE 1-C 

Absolute frequencies of vowels, high frequency consonants, 
medium fre'^uency consonants, and low frequency consonants appearing 
in five sets of Government plain- text telegrams, each set containing 



10,000 letters. 



Message 

No. 


Vowels . 


High Froq. 
Consonants. 


Medivun Freq. 
Gonsonr nts . 


Low Freq. 
Consonants. 


1 


3993 


3527 


2329 


151 


2 


3985 


3414 


2457 


144 


3 


4042 


3479 


2356 


123 


4 


3926 


5572 


2356 


144 


5 


3942 


3546 


2389 


123 


Totals 


19,388 


17,538 


11,889 


685 50,000 



REF ID:A64644 



- 120 - 



lABlJ; 2-B 

Absolute frecuencios of lettei's aiipopring in the combined five 
sets of messages totc.lllng 50,000 letters arranged according to 
frequencies . 



E -6498 


. I -3676 


C -1534 


I - 


967 


X 


- 231 


T -4505, 


G -3058 


F -1416 


G - 


819 


Q 


- 175 


N -3975 


D -2122 


P -1335 


W - 


780 


K 


- 148 


R -3788 


L -1821 


U -1300* 


V - 


766 


J 


- 82 


0 -3764 


H -1694 


M -1237 


B - 


487 


Z 


- 49 



A -5683 

TABLE 2-C 

Absolute frequencies of vowels, high freqiicncy consonants, 
medium frequency consonants, and lov< frequency consonants appearing 
in t!he combined five sots of messages totalling 50,000 letters. 

Vowels 19,888 

High fi'requoncy Consonants (D, N, R, S, and T) 17,538 

Medium Frequency Consonants (B , C, F, G, H, L, M, P, V and W) 11,889 

Low Frequency Consonants (J", K, Q, X and Z) 685 

Totai' ■ 50,000 



TABLE 2-D 

Absolute frequencies ■ of letters as initial letters of 10,000 
T/ordp found in dovernmi'nt plain- te?:t telegrams. 

(l) Arranged alphahe bD cally 



A - 


905 


G - 


109 


L - 19G 


Q 


- 30 


V - 


77 


B - 


287 


H - 


272 


M - 384 


R 


- 611 


7/ - 


320 


C - 


664 


I - 


34-1 


N - 441 


S 


- 965 


X - 


4 


D - 


525 


J - 


44 


0 - 646 


T 


-1253 


Y - 


88 


E - 
F - 


390 

855 


K - 


23 


P - 453 


U 


- 122 


Z - 


12 



Total 10,000 



(2) Arranged according to absolute frequencies. 



T -1253 


R 


- 611 


M - 


384 


L - 


196 


J - 


44 




B 


- 525 


I - 


544 


U - 


122 


Q. - 


30 


A - 9b5 


N 


- 441 


W - 


320 


G - 


109 


K - 


23 


F - 855 


P 


- 433 


B -■ 


287 


Y - 


38 


Z - 


12 


C -..654 
0 - 646 


E 


- 390 


H - 


272 


V - 


77 


X - 


4 



Total 10,000 



REF ID : A64644 

- 130 - 

TABLE 2-E 

Absoltite frequtjncies of loLtere ag finn.1 letters of 10,000 
words found in Govormnf'nt plfin-text telngrnins . 





(1) 


Arranged alphabetically. 






A - 269 


Ct - 226 


L - 354 


Q - 8 


V - 4 




B - 22 


II - 450 


M - 154 


R - 769 


W - 45 


4* 



C - 86 


I - 


22 


N - 872 


S - 962 


X - 113 


D -1002 


J - 


6 


0 - 5Y5 


T -1007 


Y - 866 


E -1628 
P - 252 


K - 


53 


P - 213 


U - 51 


Z - 9 











Total 


10,000 


(2) 


Arranged according to absolute f i.'oquf nc3os. 


E -1628 


P - 769 


F ■ 


- 252 


C - 86 


1-22 


T -1007 


0 - 575 


G 


- 225 


K - 53 


Z - 9 


D -1002 


H - 450 


P 


- 213 


W - 45 


Q - 8 


S - 962 


L - 354 


M 


- lo4 


U - 31 


j - 6 


N - 872 


A - 269 


X 


- 116 


B - 22 


V - 4 


Y - 866 




















To b-.l 


10,000 








TABLE 3 






Relative frequencies of 


letters 


appearing in 1 


,000 letter; 


brsed upon table 2. 












(1) 


Arranged alphobc ti c lly 




A - 73.66 


G - 16.38 


L 


- 36.42 


Q - 5.50 


7 - 15.32 


B - 9.74 


H - 33.88 


M 


- 24.74 


R - 75. 


W - 15.60 


C - 30.68 


I - 73.52 


K 


- 79.50 


S - 61. IL 


X - 4.62 


D - 42.44 


J - 1.64 


0 


- 75.28 


T - 91.9C 


y - 19.34 


E -129.96 


K - 2.96 


P 


- 26.70 


U - 26. Of. 


Z - .98 


F - 28.32 




















Total 


1000.00 




(2) Arranged 


'’ccording to fr:qu'>r,cy. 




E -129.96 


I - 73.52 


C 


- 30.68 


y - 19.3- 


X - 4.62 


T - 91.90 


S - 61.16 


F 


- 28.32 


G - 16.38 


Q - 3.50 


N - 79.50 


D - 42. 4i 


P 


- 26.70 


W - 15.60 


K - 2.96 


R - 75.76 


L - 36.42 


U 


- 26.00 


V - 15.32 


J - 1.64 


0 - 75.28 


H - 33.88 


M 


- 24.74 


B - 9.74 


Z - .98 


A - 73.66 













■Toto.l 1000.00 






REF _I!p^^A64644 



TA3UI 3 (Gont) 

(4) (5) (6) 

High Freq. Jiodiiim Frequency Low Freq. 

Consonnntu Gonsorxnnts Consonants 

D - 42.44 B - 9.74 L - 36.42 X - 4.62 

H - 79.50 G - 30.68 M - 24.74 Q - 3.50 

R - 75.76 F - 28.52 P - 26.70 K - 2.96 

S - 61.16 G - 16.56 V - 15.52 J - 1.64 

T - 91.90 H - 33.88 W - 15.60 Z - .98 



350.76 



237.78 13.70 

Total — 1000.00 



TABLE 4 



Frequency Distribution for 10,000 letters of literary English, 

as compiled by Hitt.l 

A. A-lphabo ti cally arranged. 



A - 778 


G 


- 174 


L - 372 


Q - 8 


V 


- 


112 


B - 141 


H 


- 595 


M - 288 


R - 651 


W 


- 


176 


C - 296 


T 


- 667 


M - 686 


S - 622 


X 


— 


27 


B - 402 


J 


- 51 


0 - 807 


T - 855 


Y 


— 


196 


E -1277 
F - 197 


K 


- 74 


P - 225 


U - 308 


Z 




17 




B. 


Arranged according to 


frequency. 








E -1277 


R 


- 651 


U - 308 


Y - 196 


K 


— 


74 


T - 855 


S 


- 622 


C - 296 


W - 176 


J 


- 


51 


0 - 807 


H 


- 595 


M - 288 


G - 174 


X 


- 


27 


A - 778 


D 


- 402 


P - 223 


B - 141 


Z 


— 


17 


Jr - 686 
I - 667 


L 


- 372 


F - 197 


V - 112 


Q 


— 


8 



TA^E 5 

Frequency Distribution for 10,000 letters of telegnphic Englislj 

as compiled by Hitt. 



A - 813 
B - 149 
C - 306 
D - 417 
E -1319 
F - 205 



A. Alphabetically arranged . 

- 201 L - 392 Q - 3f 

- 386 M - 273 R - 67'i 

- 711 N - 718 S - 65e 

- 42 0 - 844 T - 634 

- 88 P - 243 U - 32] 

Arranged according to freguenc:^ 



E 


-1319 


S 


- 656 


D 


- 521 


F - 


205 


K - 


88 


a 


T- 844 


T 


- 634 


G 


- 506 


G - 


201 


X - 


51 


A 


- 813 


D 


- 417 


M 


- 275 


?/ - 


166 


J - 


42 


N 


- 718 


L 


- 392 


P 


- 243 


B - 


149 


Q - 


38 


I 


- 711 
T 677 


H 


- 386 


Y 


- 208 


V - 


136 


Z - 


6 



IJitt, Capt. Parker. Mani:ial for the Solution of Military Ciphers. 
Arroy Service Schools Press, -^^’orb Leavenworth, Kansas, 1916. 



FIRST LETTER 



ffl * ‘ *5 

i't *\\ 



■ ' ■ ' ' . ’ ” SSGOSli iiSTTlE' ' " • "5 jR Tft-fca 

B & D S-P & H I JZ L M N 0 P O R S T ' 




illllMMMMMMlMMMlM 

EEDDEiQBBEHHEEEESEHIlEBESBHKHMB 




■ , ■V' I |J» I.. , 

■ . ' ■ »1 * 



rriStQe 2*2 



TABLE a, 

PBEQOEJlCr DJSTEIBUTION OF DIGRAPHS 

Based on 5O|Q0O letters of Government plai 
text telegrams. 

Reduced to 5»000 digraphs 



5,000 

-9» 24s 





























ID:A64644 

TABLE 7-A 







THE 438 


dift;rf.nt digra.phs 


OF 






i 

i 

I 




TABLE 6 


ARR^iNGED 


ACCORDING 


TO 








THEIR 


i\PS0LUTE FREQUENGIEvS. 






M 

E M 


111 


U R 


3 1 


aE 


1 a 


R R 


1 1 


R E ’ 


9 ri 


!nI 1 


3 0 


E F 


1 8 


U E 


1 1 


E R 


tJ7 


H 1 


3 0 


IM 0 


1 8 


F T 


1 1 


N T 


a 2 


E L 


29 


P R 


1 8 


S U 


1 1 


T H 


1. 0. 


R T 


2 8 


A 1 


1 7 


Y F 


1 1 


0 N 


11 


L A 


2 8 


H H 


1 7 


Y 8 


1 1 


1 N .. 


1 5. 


R 0 


2 8 


, P 0 


1 7 


Y 0 


1 0 


T E 


7 1 


t A 


2 R 0 


1 7 


F E 


1 0 


A I'l 


6 4 


L L 


8 7 


T R 


1 7 


1 F 


1 0 


0 R 


6 4 


A D 


2 7 


D 0 


1 6 


L Y 


1 0 


S T . 


5 3 


0 1 


2 7 


D T 


1 5 


0 


1 0 


E D 


6 0 


E 1 


2 7 


1 X 


1 5 


8 P 


1 0 


I\f E 


5 7 


1 R 


2 7 


Q U 


1 5 


Y E 


9 


V E ' 


5 7 


) T 


27 


S 0 


1 5 


F R 


9 


e 


5 4 


N G 


2 7 


Y T 


1 5 


1 i4 


9 


N u 


i? 2 


i v-l E 


8 6 


A C 


1 4 


L D 


9 


TO ; 


S 0 


N A 


2 6 


A hi 


1 4 


(4 I 


9 


B E 


4 9 3 H 


2 6 


C H 


1 4 


R F 


9 


A 


.4 7 


1 V 


2 5 


C I 


1 4 


R C 


9 


T 1 T 


.4 5 


PP 


8 5 


E h-l 


1 4 


R p< 


9 


A Hi 


^4 4 


0 M 


8 5 


G E 


1 4 


R Y 


9 


E E. 


„4 2 


0 P 


2 5 


U S 


1 4 


0 D 


8 


R T 


4 3 


IM S 


2 4 


P A 


1 4 


N IM 


8 


A y 


4 1 


S A 


2 4 


P L 


1 3 


0 F 


8 


C 0, 


.4 1 


.1 L 


23 


R P 


1 3 


1 A 


8 


1 0 


4 1 


P E 


2 3 


S C 


1 3 


H U 


H 


T Y 


-4 1 


1 C 


2 2 


W 1 


1 3 


L T 


'8 


F 0... 


-4 0 


W E 


2 2 


M 14 


1 3 


M P 


8 


F 1 , 


39 


U iM 


2 1 


D S 


1 3 


0 C 


8 


R A 


39 


C A 


2 0 


A U 


1 3 


0 w 


8 


E T 


3 7 


E P 


2 0 


1 E 


1 


P T 


8 


0 u_ 


3 7 


.E'V 


8 0 


L 0 


U G 


8 


L £ 


3 7 


G H 


2 0 


A P 


1 2 


A V 


7 


ivi A.., 


3 6 


H A 


3 0 


D R 


1 2 


B Y 


7 


T W 


-3 6 


H E 


2 0 


E y 


1 2 


C 1 


7 


E A 


3 5 


H U 


. 8 0 


A Y 


1 2 . 


E H 


7 


I 


3 5 


L 1 


8 0 


E U 


1 2 


0 A 


7 


S f 


3 4 


3 S 


1 9 


0 D 


1 2 


E W 


7 


° 1-^ 


3 3 


T T 


19 . 


S F 


3. 2 


E X 


7 


H L 


. 3 3 


1 G 


1 9 . 


U S 


1 2 


G A 


7 


A L 


3 2 


J'l C 


1 9 


U T 


1 2 


1 P 


7 


C E 


3 2 


0 L 


1 9 


.V 1 


1 2 


i\l U 


7 


0 A' 


3 2 


.0 T 


1 9 


W A 


1 2 


0 V 


7 


£ C 


,3 2 


T 3 


1 9 


.F F 


1 1 


R G 


7 


R S 


3 1 


W U 


1 9 


P P 


3. 1 


R iM 


7 



, ;v ■ : 

i* ; ; :: — 

1 Thq 3-8 cU-graphs "bove this line corapor;e ?5'^ of the total. 
,1 Ibe 55 digraphs above this lino conipoce GO'? of thu total. 

* thc^ 117 digr.’phs above this line compose 7.5'? of the total. 



KEF ID:A64644 

13 4 



TABLE 7 A CONCLUDED 



T F 


7 


D B 


4 


H P 


3 


X A 


2 


L G 


i 


T H 


7 


0 C 


4 


fM V 


3 


X C 


2 


L M 


1 


X T 


7 


D N 


4 


M W 


3 


X 1 


2 


L N 


1 


A B 


6 


D W 


4 


0 H 


3 


X P 


9 


i'1 D 


1 


A G 


6 


E B 


4 


A H 


a 


Y B 


2 


M F 


1 


b L 


6 


E G 


4 


A K 


3 


Y L 


3 


M H 


1 


0 0 


6 


E Y 


4 


B 1 


3 


Y 


2 


M J 


1 


Y A 


6 


G T 


4 


B R 


2 


Z E 


2 


N Q 


1 


G 0 


6 


H S 


A 


B U 


3 


G G 


1 


0 J 


1 


1 D 


6 


H S 


4 


D G 


3 


A J 


1 


0 X 


1 


K E 


6 


N H 


4 


U H 


3 


R J 


1 


P B 


1 


L S 


6 


M R 


4 


D Q 


2 


P M 


1 


P C 


1 


M B 


6 


0 B 


4 


A 0 


3 


R 8 


1 


P 0 


1 


P 1 


6 


P M 


4 


0 Y 


3 


B T 


1 


P IM 


1 


P S 


6 


R W 


4 


F C 


3 


c n 


1 


P V 


1 


F 


6 


S i^l 


4 


F L 


3 


C F 


1 


P W 


1 


T C 


6 


• S W 


4 


G C 


3 


C 1.1 


1 


P Y 


1 


T D 


6 


W H 


4 


G F 


3 


C N 


1 


Q M 


1 


T wl 


6 


Y C 


4 


G L 


3 


C S 


1 


P R 


1 


U L 


6 


Y U 


4 


G P 


3 


C W 


1 


R J 


1 


V A 


6 


Y R 


4 


G U 


3 


C Y 


1 


R K 


1 


Y N 


6 


P H 


3 


H D 


3 


D J 


1 


S K 


1 


C L 


5 


P U 


3 


H H 


3 


n Y 


1 


S V 


1 


U M 


5 


R H 


3 


1 B 


3 


E J 


1 


vS Y 


1 


D P 


5 


S B 


3 


1 K 


3 


A E 


1 


T G 


1 


D U 


5 


S P/l 


■3 


1 Z 


3 


U 0 


1 


T Q 


1 


0 1 


5 


T B 


3 


J E 


2 


Y U 


1 


T 1 


1 


U A 


5 


U B 


3 


J 0 


2 


E Z 


1 


U F 


1 


U 1 


5 


U C 


3 


J U 


3 


F n 


1 


U V 


1 


F A 


5 


U U 


3 


K 1 


3 


F G 


1 


V 0 


1 


G 1 


5 


Y P 


3 


L M 


3 


F ^yl 


1 


V T 


1 


G H 


5 


C C 


3 


L R 


3 


F P 


1 


W L 


1 


H F 


5 


A W 


3 


L U 


3 


F W 


1 


W R 


1 


IM L 


5 


D L 


3 


L V 


3 


F Y 


1 


w s 


1 


N M 


5 


D V 


3 


L W 


3 


G n 


1 


Vi Y 


1 


N Y 


5 


A A 


3 


M R 


3 


G J 


1 


X D 


1 


R L 


5 


E U 


3 


M T 


3 


G M 


1 


X E 


1 


R U 


5 


0 E 


3 


M U 


3 


G W 


1 


X F 


1 


R V 


5 


Y 1 


3 


M Y 


3 


H B 


1 


X H 


1 


S D 


5 


F S 


3 


N B 


3 


K L 


1 


X IM 


1 


S H 


5 


F U 


3 


N K 


9 


H P 


1 


X 0 


1 


T L 


5 


G N 


3 


0 G 


3 


H Q 


1 


X R 


1 


T U 


5 


G S 


3 


0 K 


9 


H W 


1 


X S 


1 


U M 


5 


H C 


3 


P F 


3 


H Y 


1 


Y G 


1 


A F 


4 


H N 


3 


R B 


3 


J A 


1 


Y H 


1 


B A 


4 


L B 


3 


S G 


3 


K A 


1 


Y W 


1 


B 0 


4 


L C 


3 


S L 


9 


K C 


1 


Z A 


1 


C K 


4 


L F 


3 


T P 


3 


K L 


1 


Z 1 


1 


C K 


4 


L P 


3 


U P 


3 


K N 


1 






C U 


4 


^/l C 


3 


W N 


3 


K B 


1 


Total 


5000 



lil 



REF ID 1^64 644 



It , “ 

- 155 - 



TABLE 7-B 



■ tl!E 18 DlQTL'PtlG GOM'-OSTNG ?5'J OF THE DICSL^PHS 
IN TABLE HO. 6. ARRANGED ALPIL' BETI^ALLY 
ACGORT^ING TO THEIR INITIAL LETTERS, 



iiv 





L"! ' 


• 


(1) 






AND 


ACCORDING TO THElR 






FINAL 


LETTERS. 






AN 


64 


RE 


- 98 




ED 


60 


1. J 

SE 


49 




SN 


111 


ST 


65 


-■ 


Er ' 


87 






3T' 

% 


ES 


S4 


TE 


71 








TH 


78 


r 

d* 




, 75 


TO 


50 


V 

«•> 


p ' 


' 52 


VE 


57 


V 

c 


P 

NT 


57 

82 


Total 


1249 




GN 


77 






JG 


DR ^ 


64 


. 





t 



(?) 

AND ACCORDING TO THE-IR 
/J3SOLUTE FREQUENCIES. 



AN 


64 


:RE 


98 


EN 


111 


SE 


49 


ER 


87 


ST 


63 


ED 


60 






ES 


54 


TH 


78 






TE 


71 


IN 


75 


TO 


50 


NT 


82 


VE 


57 


NE 


57 


Total 


1249 


ND 


52 






ON 


77 


■ 




OR 


64 








2 . « 




tL 



ID : A64644 

TABLE 7-C 



THE 03 DIGRAPHS COtJTOSING SOp; OF T!IE 5000 DIGRAl^HS OF TABLE 6, 
ARRANGED ALPHABETICALLY ACCORDING TO THEIR INITIAL LF.TTERS> 



(1) (i?) 

AND ACCORDING TO THEIR AND ACCORDING TO TlffilR 





FINAX 


LETTERS 






ABSOLUTE 


FRSOUENCIES 




A L 


3 2 


N D 


5 2 


A ivj 


6 4 


I'J T 


8 2 


A I'J 


6 4 


N E 


5 7 


A T 


4 7 


R E 


5 7 


A R 


4 4 


N 1 


3 0 


A R 


4 4 


1'] 0 


5 2 


A S 


4 1 


IM T 


8 2 


A H 


4 1 


I'i 1 


3 0 


A T 


4 7 


0 N 


7 7 


A L 


3 2 


0 N 


77 


C £ 


3 2 


0 H 


to 4 


C U 


4 1 


0 R 


6 4 


C 0 


4 1 


0 U 


3 7 


C E 


3 2 


0 U 


3 7 


D A 


3 2 


R A 


3 9 


0 E 


3 3 


R E 


9 8 


D E 


3 3 


R E 


9 B 


D A 


3 2 


R T 


4 2 


E A 


35 


R 1 


3 0 






R A 


3 9 


E C 


3 2 


R 0 


2 8 


E M 


111 


R a 


3 1 


E D 


6 0 


R S 


3 1 


E R 


R 7 


R t 


3 0 


E E 


4 2 


R T 


4 2 


E D 


6 0 


R 0 


2 8 


E L 


29 






E 8 


5 4 






E N 


111 


a E 


4 9 


E E 


4 2 


S T 


6 3 


E K 


« 7 


a 1 


3 4 


E T 


3 7 


a E 


4 9 


E a 


5 4 


a T 


to 3 


E A 


35 


8 1 


3 4 


£ T 


3 7 






E C 


3 2 










T A 


2 8 


E L 


2 y 


T H 


7 8 


F 1 


3 9 


T E 


7 1 






T E 


7 1 


K 0 


4 0 


T H 


7 8 


F U 


4 0 


T 0 


5 0 






T 1 


4 5 


F 1 


3 9 


T 1 


4 5 


H 1 


3 3 


T 0 


5 0 


H 1 


3 3 


T Y 


4 1 


H T 


2 a 


T W 


3 6 


H T 


2 8 


T W 


3 6 






T Y 


4 1 






T A 


2 8 


1 H 


7 5 






1 N 


7 5 






1 0 


4 1 


U R 


3 1 


1 U 


4 1 


U R 


3 1 


1 S 


35 






1 a 


3 5 






L A 
L E 


28 
3 7 


V E 


5 7 




3 7 
2 8 


V E 


5 7 


Total - 


2495 


L E 
L A 


Total - 


2495 


ul A 


36 






Hi A 


3 6 







REF ID:A64644 

S h • fl* 

- I5v L' 

t* 

' tAELE 7-ii ' ^ 

V -iHE 111 EIGR/J’HS eSliROSlrTG 75% OF THE 5O00 Dl&U'.PHS OF 
ii'.BLE 6j ARR/xNGED ALPH/'BETIC/LLY ACCORDING TO THEIR 
r ' IKITIAi. LETTERS, 

'■ (1) AND ACCORDING t6 THEIR FINAL LETTERS. 





A C 


1 4 


H A 


2 0 


p A ■ 


1 4 


. - 


A D 


27 


H E 


2 0 


P E 


2 3 


. b 


AT 


17 


H i 


3 3 


P 0 


1 7 




A L 


3 2 


H 0 


2 0 


P R 


1 8 


ft H 


A ivl 


1 4 


H R 


1 7 






, 1 


A N 


6 4 


H'T 


2 8 


Q U 


1 5 


r- 


A R 


4 4 










■jt . 


A S 


4 1 


1 C 


2 2 


R A 


39 




A T 


4 7 


i E ■ 


1 3 


R D 


1 7 




A'U 


1 3 


1 G 


1 9 


R E 


9 8 


jr 

T - 


1 




1 L 


23 


R 1 


3 0 


f i 


BE 


1 a 


1 1>I 


7 5 


R U 


2 8 


:i • 


' 




1 0 


4 1 


R S 


3 1 


1 '' 


C A 


2 0 ' 


1 K 


27 


R T 


4 2 


<1 


C E 


3 2 


1 S 


3 5 






, «' 


CH 


1 4 


1 T 


27 


S A 


24 




co 


4 1 


1 V 


2 5 


S £ 


4 9 


il. 


C T 


14 


1 X 


1 5 


S H 


26 




•1 








8 1 


3 4 


i: . 


D A 


3 2 


L A 


2 8 


8 (5 


1 5 


» 


D E 


3 3 


L E 


37 


8 8 


19 




D 1 


27 


L 1 


2 0 


8 T 


6 3 


1 •. 


D 0 


16 


L L 


27 






! 


D S 


1 3 


L 0 


1 3 


T A 


2 8 




D T 


15 






- T E 


7 1 




• 




M A 


3 6 


T H 


7 8 




E A 


35 


M E 


2 6 


T 1 


4 5 




E C 


3 2 






T 0 


5 0 




E D 


6 0 


N A 


2 6 


T R 


1 7 




E E 


4 2 


N C 


1 9 


T S 


19 




E F 


1 8 


N 0 


5 2 


T T 


19 




E 1 


27 


H E 


5 7 


T 


3 6 




E L 


29 


N G 


27 


T Y 


4 1 




E M 


14 


N 1 


3 0 






»i * 


E N 


111 


FM 0 


1 8 


U N 


2 1 




E P 


2 0 


N S 


24 


U R 


3 1 


. 

■ 


E R 


8 7 


N T 


8 2 


p 




— j' 

^ t • 


. 'E S 


5 4 






V E 


5 7 


* 


V £'T 


3 7 


0 F 


2 5 








E V 


2 0 


0 L 


1 9 


W E 


2 2 








0 M 


2 5 


W U 


19 




F 1 


39 


0 N 


7 7 








F 0 


4 0 


0 P 


2 5 


Y T 


15 




G E 


14 


Q R 
d S 


6 4 
1 4 


Total - 


3745 




G H 


2 0 


0 T 


1 9 






’ 1* 




/ -• »m ,m 


- 


3 7 






- 




. 


- ”ja>' 


— k ^ '1 




■ 


:i 


l_l mi 




-m 


; -3 : rLT’l 





- ±iitj — 

REF ^ID : A64644 

TABLE 7-u (ConcludPd) 



(2) 


IJD ACCORDING 


TO THEIR 


ABSOLUTE 


FREQUENCIES. 


A i\l 


6 4 


H 1 


33 


P E 


2 3 


A T 


4 7 


H T 


2 8 


P H 


1 8 


A K 


4 4 


H A 


2 0 


P 0 


1 7 


A S 


4 1 


H E 


2 0 


P A 


1 4 


A L 


3 a 


H U 


2 0 






A n 


2 7 


ri K 


17 


U IJ 


1 5 


A 1 


17 










A C 


1 4 


1 N 


7 5 


H E 


9 8 


A M 


1 4 


1 0 


4 1 


K T 


4 2 


A U 


1 3 


1 S 


3 5 


R A 


39 






1 R 


27 


R S 


3 1 


B E 


1 a 


1 T 


27 


R 1 


3 0 






1 V 


2 5 


R 0 


28 


C 0 


4 1 


1 L 


2 3 


R 0 


1 7 


C E 


3 2 


1 C 


22' 






C A 


2 0 


1 G 


1 9 


vS T 


6 3 


C H 


14 


1 X 


1 5 


S E 


49 


C T 


1 4 


1 E 


1 3 


S 1 


3 4 










S H 


2 6 


0 E 


3 3 


L E 


37 


8 A 


2 4 


D A 


3 2 


L A 


28 


S 3 


1 9 


D 1 


2 7 


L L 


27 


3 U 


1 5 


D 0 


16 


L 1 


2 0 






D T 


IS 


L 0 


1 3 


T H 


7 8 


D S 


1 3 






T E 


7 1 






M A 


3 6 


T 0 


5 0 


E N 


111 


I'/i E 


26 


T 1 


4 5 


E K 


8 7 






T Y 


4 1 


E D 


6 0 


I>1 T 


8 2 


T V/ 


3 6 


E S 


5 4 


N E 


5 7 


T A 


2 8 


E E 


4 2 


N D 


5 2 


T 3 


19 


E T 


37 


!M 1 


3 0 


T T 


19 


E A 


3 5 


l\| G 


2 7 


T R 


1 7 


E C 


3 2 


iv| A 


26 






E L 


2y 


0 0 


4 


U R 


3 1 


E 1 


2 7 


U C 


1 y 


U N 


2 1 


E 


2 0 


H 0 


1 8 






E V 


2 0 






V E 


5 7 


E F 


1 8 


0 N 


7 7 






E !-.1 


1 4 


0 K 


6 4 


W E 


2 2 






0 U 


37 


W 0 


19 


F 0 


4 0 


0 F 


2 5 






F 1 


3y 


0 M 


2 5 


Y T 


1 5 






0 P 


2 8 






G H 


2 0 


0 L 


^ y Total - 


3745 


G E 


1 4 


0 T 


1 9 










0 S 


1 4 







TABLE 7-E 

ALL THE 438 DIGIL\PHS OF TABLE 6, A'’!L'NGED FIRST i’^LPHA- 
BETICALLY ACCORDING TO THEIR INITI/J. LETTERS AND THEN /iPHA- 
BETTCALLI ACCORDING TO THEIR FINAL lETTERS. 

(SEE TABLE 6. RE/D ACROSS THE ROWS) 



REF ID : A64644 



■ ■ - 159 - 

T.\BLE 8 

THE 438 DIFFERENT DIGRAPHS OF TABLE 6 .'JRRANGED FIRST 
/■T.PTTfBETTr. ;.T.T. Y ACCORDING TO THEIR INITIAL LETTERS, AND THEN 
ACCORDING TO THEIR ABSOLUTE FREQUENCIES UNDER EACH INITIAL 
LETTER. 



A N 


6 4 


C 0 


4 1 


E R 


8 7 


G H 


2 0 


A T 


47 


CE 


3 2 


E D 


6 0 


G E 


1 4 


A H 


4 4 


C A 


2 0 


E S 


5 4 


G A 


7 


. A S 


4 1 


C H 


14 


E E 


4 2 


G 0 


6 


- A L 


3 2 


C T 


14 


E T 


3 7 


G 1 


5 


A D 


27 


C 1 


7 


E A 


3 5 


G R 


5 


A 1 


1? 


C L 


5 


E C 


3 2 


G T 


4 


; ^ ^ 


1 4 


C K 


4 


E L 


29 


G IM 


3 


' A ivl 


1 4 


C 


4 


E 1 


2 7 


G S 


3 


' A LI 


1 3 


C U 


4 


E P 


2 0 


G C 


2 


- A P 


1 2 


C C 


3 


E V 


2 0 


G F 


2 


A Y 


1 2 


C D 


1 


E F 


1 8 


G L 


2 


• A V 


7 


C F 


1 


E I'l 


1 4 


G P 


2 


I A B 


fi 


C M 


1 


E 0 


1 2 


G U 


2 


• AG 


6 


C N 


1 


E Q 


1 2 


G 0 


• 1 


A F 


4 


C S 


1 


E N 


L' 1 1 1 


G G 


1 


. A A 


3 


C w 


1. 


E H 


7 


G J 


1 


A 


3 


C Y 


1 


E W 


7 


G 


1 


A H 


2 






E X 


7 


G \i 


1 


. A K 


2 


0 E 


3 3 


E B 


4 






A 0 


2 


U A 


3 2 


E G 


4 


H 1 


3 3 


A E 


1 


1) 1 


2 7 


E Y 


4 


H T 


2 8 


A J 


1 


1) 0 


16 


E U 


3 


H A 


2 0 






U T 


15 


E J 


1 


H E 


2 0 


. B E 


1 8 


b S 


1 3 


E Z 


1 


H 0 


2 0 


-■ B Y 


7 


U R 


12 






H K 


1 7 


'B L 


6 


b D 


8 


F U 


4 0 


H U 


8 


B A 


4 


LI F 


8 


F 1 


39 


H F 


5 


. B 0 


4 


U M 


5 


F F 


1 1 


H S 


4 


.. B 1 


. 2 


U P 


5 


F T 


1 1 


H C 


3 


B H 


2 


D U 


5 


F E 


1 0 


H ivl 


3 


6 U 


2 


U 13 


4 


F K 


9 


H D 


2 


8 J 


1 


u c 


4 


F A 


5 


H M 


2 


. B ul 


1 


IJ N 


4 


F S 


3 


H B 


1 


• B S 


1 


b W 


4 


F U 


3 


H L 


1 


: B T 


1 


b L 


3 


F C 


S 


H P 


1 






b V 


3 


F L 


2 


H 0 


1 






b G 


2 


F D 


1 


H W 


1 






b H . 


2 


F G 


1 


H Y 


1 






b Q 


2 


F M 


1 










b J 


1 


F P 


1 






, 




b Y 


1 


F W 


1 














F Y 


1 








0 V 7 R N 7 

0 U 6 R F 6 

0 i 5 R L 5 

OB 4 R U 5 

0 E :3 R V 5 

OH :5 R W 4 

0 G P, R H 3 

OK R R B S 

0 Y R J 1 

0 J 1 R K 1 

OX 1 



REF ID : A64644 



- Ill - 



TmE S CONCLUDED. 



X ‘ 





S T 


6 3 


U R 


3 1 


X T 


7 




Q E 


4 9 


U N 


2 1 


X A 


2 




43 1 


5 4 


U S 


1 2 


X C 


2 


. 


a H 


26 


U T 


1 2 


X 1 


2 




S A 


2 4 


U E 


1 1 


X P 


2 


t 


.3 s 


19 


U G 


8 


X D 


1 




S 0 


15 


U L 


6 


X E 


1 




c 


1 3 


U A 


5 


X F 


1 






1 2 


U 1 


5 


X H 


1 




s u 


1 1 


U M 


5 


X N 


1 




S P 


1 0 


U B 


3 


X U 


1 




^ D 


5 


U C 


3 


X R 


1 




S P 


5 


U D 


3 


X S 


1 




S N 


4 


U P 


2 






1 




4 


[) F 


1 


Y T 


1 b 




S B 


3 


U 0 


1 


Y F 


1 1 


— t 1 


S IM 


3 


U V 


1 


Y S 


1 1 




B G 


2 






Y U 


1 0 




. 8 L 


2 


V E 


5 7 


Y E 


9 




-S K 


1 


V 1 


1 2 


Y A 


6 


1 


.-S V 


1 


V A 


•6 


Y N 


6 


’ 1 


SY 


1 


V 0 


1 


Y C 


4 








V T 


1 


Y D 


4 




T H 


7 8 






Y R 


4 




• J E 


7 1 


U E 


2 2 


Y 1 


3 




T 0 


5 0 


W 0 


19 


Y P 


3 


1 


- T 1 


4 5 


W 1 


1 3 


Y B 


2 




. T Y 


4 1 


W A 


1 2 


Y L 


2 




- T W 


36 


W H 


4 


Y M 


2 




- T A 


2 B 


W N 


2 


Y G 


1 




T S 


19 


W L 


1 


Y H 


1 




T T 


19 


W R 


1 


Y U 


1 




T H 


17 


W S 


1 


Y W 


1 




T F 


7 


Vi/ Y 


1 








T iJ 


7 






Z E 


2 




T C 


6 






Z A 


1 




T D 


6 






Z 1 


1 




T I'^l 


6 












T L 


5 






Total - 


5000 




T U 


5 












T B 


3 












T P 


2 












T G 


1 












T bJ 


1 












T Z 


1 












K ^ 



(Note: For arrangement alphabetically first under initial 

letters and then under final letters, see Table 6.) 



WE^o ID:A64644 
g?ABLE 9-A 

THS 438 DIFFjLREI^T DIGH/PHS OF TABLE 6 A'mANGED FIRST 
ALPHABETICALLY ACCORDING TO THI'IR FINAL LETTERS AND THEN 
ACCORDING TO THEIR ABSOLUTE I’REQUENCIES . 



H A 


3 9 


E C 


3 2 


R E 


9 8 


W G 


2 7 


Iv) A 


36 


1 C 


2 2 


T E 


7 1 


1 G 


1 9 


E A 


35 


N C 


19 


IM E 


5 7 


U G 


8 


D A 


3 « 


A C 


1 4 


V E 


5 7 


G 


7 


L A 


3 8 


8 C 


13 


8 E 


4 y 


A G 


6 


T A 


« 8 


H C 


9 


E E 


4 2 


E G 


4 


N A 


26 


0 C 


8 


L E 


3 7 


D G 


2 


S A 


24 


T C 


6 


D E 


3 3 


(3 G 


2 


C A 


20 


IJ C 


4 


C E 


3 2 


S G 


2 


H A 


2 0 


Y C 


4 


■•1 E 


2‘6 


F G 


1 


P A 


1 4 


c c 


3 


P E 


2 3 


G G 


1 


W A 


1 2 


H C 


3 


W E 


2 2 


L G 


1 


1 A 


8 


L C 


3 


H E 


2 0 


T G 


1 


G A 


7 


M C 


3 


8 E 


1 8 


Y G 


i 


0 A 


7 


u c 


3 


G E 


1 4 






V A 


6 


F C 


2 


1 E 


1 3 


T H 


7 8 


Y A 


6 


G C 


2 


U E 


1 1 


8 H 


2 6 


F A 


5 


X C 


2 


F E 


1 0 


G H 


2 0 


U A 


5 


K C 


1 


Y E 


9 


C H 


1 4 


B A 


4 


P C 


1 


K E 


6 


E H 


7 


A A 


3 






0 E 


3 


N H 


4 


X A 


2 


E D 


6 0 


J E 


2 


W H 


4 


J A 




N D 


5 2 


Z E 


2 


n H 


3 


K A 


1 


A 0 


2 7 


A E 


1 


P H 


3 


Z A 


1 


0 


1 7 


X E 


1 


R H 


3 






0 D 


1 2 






A H 


2 


A B 


6 


L D 


9 


0 F 


2 5 


0 M 


2 


M B 


6 


L) D 


8 


E F 


1 8 


{. H 


1 


D B 


4 


1 D 


6 


S F 


1 2 


H H 


1 


E B 


4 


T D 


6 


F F 


1 1 


X H 


1 


0 B 


4 


« Q 


5 


Y F 


1 1 


Y H 


1 


L B 


3 


Y 13 


4 


1 F 


1 0 






S B 


3 


U D 


3 


N F 


y 






T B 


3 


H D 


2 


D F 


8 






U B 


3 


C D 


1 


T F 


7 






1 B 


2 


F D 


1 


R F 


6 






IM B 


2 


G D 


1 


H F 


s 






H B 


2 


M D 


1 


A F 


4 






Y B 


2 


PD 


1 


L F 


3 






H 8 


1 


X U 


1 


G F 


2 






P 8 


1 






P F 


2 














C F 


1 














F 


1 














U F 


1 














X F 


1 







REF ID:A64644 



- 14S - 

TABLE 9-A CONTINUED. 



T i 


4 5 


A L 


3 2 


F'l 


39 


£ L 


29 


-'S'l 


34 


L L 


2 7 


•H 1 


3 3 


1 L 


23 


N 1 


3 0 


0 L 


19 


■R i 


3 0 


P L 


1 3 


■D 1 


27 


B L 


6 


^E 1 


27 


U L 


6 


-L 1 


2 0 


C L 


5 


i‘A 1 


1 7 


IM L 


5 


■ W 1 


1 3 


R L 


5 


V 1 


12 


T L 


5 


ifM 1 


9 


0 L 


'3 


1 


7 


F L 


2 


7P 1 


6 


G L 


2 


■ G 1 


5 


S L 


2 


0 1 


5 


Y L 


2 


• 0 1 


5 


H L 


1 


Y 1 


3 


K L 


1 


.IB ! 


2 


W L 


1 


K 1 


'2 






X 1 


2 


0 M 


2 5 


1 i 


1 


A M 


14 






E M 


14 


A J 


1 


M I'i 


1 3 


B J 


1 


1 M 


9 


D J 


1 


R M 


9 


E J 


1 


T M 


6 


'G J 


1 


D H 


5 


N J 


1 


N H 


5 


0 J 


1 


U I'i 


5 


H J 


1 


P M 


4 






S hi 


3 


C K 


4 


H hi 


2 


A K 


2 


L hi 


2 


1 K 


2 


I M 


2 


N K 


2 


B Ivi 


1 


0 K 


2 


C M 


1 


H K 


1 


F M 


1 


S K 


1 


G li 


1 






Q hi 


1 



E N 


111 


0 P 


2'5* 


0 IM 


7 7 


E P 


2 0 


1 N 


7 5 


- R P 


1 3 


A IM 


6 4 


A P 


1 2 


U IM 


2 1 


P P 


1 1 


N IM 


8 


S P 


10 


R IM 


7 


M P 


8 


T N 


7 


1 P 


7 


Y fM 


6 


D P 


5 


D )M 


4 


L P 


3 


S iM 


4 


N P 


3 


G N 


• 3 


Y P 


3 


H N 


3 


G P 


2 


W IM 


2 


T P 


2 


C IM 


1 


U P 


2 


K iM 


1 


X P 


2 


L IM 


1 


F P 


1 


P IM 


1 


H P 


1 



X N 1 

EG 12 
TO 5 0 0 Q 

CO 41 HQ 

10 4 1 N Q 

F 0 4 0 T Q 

R 0 2 8 

HO 2 0 

WO 19 

NO 18 

P 0 17 

DO 16 

SO 15 

L 0 13 

E 0 12 

MO 10 

Y 0 10 

GO 6 

0 0 6 

BO 4 

AO 2 

JO 2 

U 0 1 

VO 1 

X 0 1 



K (-1 (-^ JO 



REF ID:A64644 

- 144 - 



TABLE a-A CONCLUDED. 



E K 


8 7 


N T 


8 2 


0 R 


6 4 


S T 


6 3 


A R 


4 4 


A T 


4 7 


U R 


3 1 


R T 


4 2 


1 R 


27 


E T 


3 7 


P R 


1 8 


H T 


2 8 


H R 


17 


1 T 


2 7 


T R 


1 7 


0 T 


19 


D R 


1 2 


T T 


19 


R R 


11 


U T 


1 5 


F R 


y 


Y T 


1 5 


G R 


5 


C T 


14 


S R 


5 


U T 


1 2 


C R 


4 


F T 


11 


N R 


4 


L T 


8 


Y R 


4 


P T 


8 


B R 


2 


X T 


7 


L R 


2 


G T 


4 


M R 


2 


M T 


2 


Q R 


1 


B T 


1 


W R 


1 


V T 


1 


X R 


1 










0 U 


3 7 


E S 


5 4 


0 U 


1 5 


A S 


4 1 


A U 


1 3 


1 S 


3 5 


8 U 


1 1 


R S 


31 


H U 


8 


N S 


2 4 


N U 


7 


S S 


ly 


L) U 


5 


T S 


1 y 


R U 


5 


0 S 


1 4 


T U 


5 


D S 


1 3 


C U 


4 


U S 


1 2 


E U 


3 


Y S 


11 


F U 


3 


L S 


6 


P U 


3 


P vS 


6 


B U 


2 


H S 


4 


G U 


2 


iv( S 


4 


J U 


2 


F S 


3 


L U 


2 


G S 


3 


\'A U 


2 


b S 


1 


Y U 


1 


c s 


1 






K S 


1 






w s 


1 






X s 


1 







1 V 


2 5 


T Y 


4 1 


E V 


2 0 


A Y 


1 2 


A V 


7 


L Y 


1 0 


0 V 


7 


K Y 


9 


R V 


5 


B Y 


7 


D V 


3 


N Y 


5 


■ i\| V 


3 


E Y 


4 


L V 


2 


l^ Y 


2 


P V 


1 


0 Y 


2 


S V 


1 


C Y 


1 


U V 


1 


D Y 


1 






F Y 


1 


T W 


3 6 


H Y 


1 


Q V/ 


8 


P Y 


1 


E W 


7 


8 Y 


1 


D W 


4 


W Y 


1 


R H 


4 






S W 


4 


1 Z 


2 


A W 


3 


E Z 


1 


l\| W 


3 


T Z 


1 


L W 


2 






C W 


1 


Total - 


5000 


F W 


1 






G W 


1 






H W 


1 






P W 


1 






Y W 


1 






1 X 


1 5 






E X 


7 






0 X 


1 








REF ID:A64644 



- 145 - 



It: 

;aU 



V4. 



TABLE 9-B 

THE 18 DIGRAPHS COIiffOSING 25% OF THE 5000 DIGRAPHS 
V-Of 'TAPLE ARRANGED ALPHi\BETICALLX ACCORDING TO" THEIR 
. FINAL LETTFJRS, 



"’'Vl- 



:■ • 

; . Airo ACCORDING TO 

TNEIR IlSriTIAL LETTERS 



H - 


Fp 


60 






52 


& : 








57 


1*1 




98 




m 


49 




ri 


71 




■ 


57 






78 




' »!■ ' 




1 


’2^N 


64 


feN 


111 


“ 


IN 


75 




.PN 


77 


^ r». 


TO 


50 


k 


1!r 


87 




OR 


64 


'T 


i. • 




r ‘ 




54 




m 


82 




^BT 


63 




Total- 


1249 



( 2 ) 

AND ACCORDING TO THEIR 
ABSOLUTE FREQUENCIES 



ED 


60 


ND 


52 


RE 


98 


■ TE 


71 


NE 


57 


' TE 


57 


SE 


49 


TH 


73 


EN 


111 


ON 


77 


IN 


75 


AN 


64 


TO 


SO 


- ER 


87 


OR 


64 


ES 


54 


NT 


82 


ST 


65 


Total - 


1249 






lE, - 



Ri^Fp ID : A64644 

TABLE 9-C 

THE 53 DIGRAPHS CCHP031!?G 50J? OF THE 5COO DIGRAPHS 
OF TABLE 6, AER;NGEU /JLPHABETIO/JLLY AGGOEDING TO THEIR FIIL\L 



LETTERS, 



(1) 


I.ND / 


.GGORDIHG TO 


THEIR 


(2) 


;iND / 


.CCOFuDING TO 


THEIR 


INITIAL LETTliRS. 




ABSOLUTE 


FrlEQDENCIES. 




DA 


32 


CO 


41 


RA 


39 


TO 


50 


EA 


35 


FO 


40 


MA 


36 


CO 


n 


LA 


28 


10 


•11 


EA 


35 


10 


41 


MA 


36 


dO 


28 


DA 


32 


FO 


40 


RA 


39 


TO 


50 


la 


28 


RO 


28 


TA 


26 






TA 


28 










AR 


44 






FR 


87 


EC 


32 


ER 


87 


EC 


32 


OR 


64 






OR 


64 






AR 


44 


ED 


60 


UR 


31 


ED 


60 


UR 


31 


ND 


52 






ND 


52 










j\S 


41 






ES 


54 


CE 


32 


ES 


54 


RE 


98 


AS 


41 


DE 


33 


IS 


35 


TE 


71 


IS 


35 


EE 


42 


RS 


31 


NE 


57 


RS 


51 


LE 


37 






VE 


57 






NE 


. 57 


A 

1 


47 


SE 


49 


NT 


82 


RE 


98 


ET 


37 


EE 


42 


ST 


63 


SE 


49 


HT 


28 


LE 


37 


AT 


47 


TE 


71 


NT 


G2 


DE 


33 


RT 


42 


VE 


57 


RT 


42 


CE 


32 


ET 


37 






ST 


63 






HT 


28 


TII 


78 






TH 


78 










OU 


37 






OU 


57 


FI 


59 






TI 


45 






HI 


33 


T?J 


36 


FI 


39 


W. 


36 


NI 


30 






SI 


34 






RI 


30 


TY 


41 


HI 


33 


TY 


41 


SI 


34 


Total - 


- 2495 


NI 


30 


Total - 


- 2495 


TI 


•i5 






RI 


30 






AL 


32 






AL 


32 






EL 


29 






EL 


29 






AN 


64 






EN 


111 






EN 


111 






ON 


77 






IN 


75 






IN 


75 






ON 


77 






AI^ 


61 







REF ID:A64644 



- 147 - 



TABLE 9-D 



the 117 DIGH/PIIS COMTOSING 75,1 OF THE 5000 DIGRAPHS OF 
TABLE 6, AJtPJJJGED ALPHABETICALLY ACCORDING TO THEIR FINAL 
LETms, 

(1) AND ACCO'-ffllNG TO THEIR INITIAL LEITERS. 



* '-(1 
C A 


3 0 


E F 


1 8 


C 0 


4 1 


A T 


4 7 


0 A 


3 2 ' 


0 F 


25 


D U 


1 6 


C T . 


1 4 


E a: 


3 5 






F 0 


4 0 


D T 


1 5 


H A, 


2 0 


1 G 


19 


H 0 


2 0 


E T 


3 7 


L A ' 


28 


IM G 


2 7 


1 0 


4 1 


H T 


28 


M A 


36 






L U 


1 3 


1 T 


2 7 


N.A 


2 6 


C H 


1 4 


N 0 


1 8 


N T 


8 2 


P A 


1 4 


G H 


2 0 


P 0 


1 7 


n T 


19 


H A 


39 


8 H 


2 6 


R U 


2 8 


R T 


4 2 


8 A 


2 4 


T H 


7 a 


S 0 


1 5 


S T 


6 3 


T A 


28 






T 0 


5 0 


T T 


19 


J 




A^l 


1 7 


W 0 


1 9 


V T 


1 5 


A C 


1 4 ' 


0 1 


2 7 










E 'C 


3 2 


E 1 


2 7 


E P 


2 0 


A U 


1 3 


1 c' 


2 2' 


F 1 


3 9 


0 P 


2 5 


0 u 


37 


N C, 


19 


H 1 


3 3 






Q U 


1 5 






L 1 


2 0 


A R 


4 4 






A.D, 


27 


IM 1 


3 0 


T R 


T7 


E V 


2 0 


.r‘D . 


6 0 


R 1 


3 0 


U R 


3 1 


1 V 


2 5 


Mcr 


5 2 


S 1 


34 


E R 


8 7 






H D 


17 


T i 


4 5 


0 R 


6 4 


T W 


3 6 










P R 


1 8 






B £ 


1 a 


a'l 


3 2 


H R 


1 7 


1 X 


1 5 


C E 


3 2 


E L 


29 


1 R 


2 7 






D E 


3 3 


1 L 


23 






T Y 


4 1 


E £ 


4 2 


L L 


2 7 


A S 


4 1 


Total — 


3745 


G £ 


1 4 


O' L 


19 


S S 


1 9 






H 1^ 


2 0 






T S 


1 9 






1 E 


1 3 


A i>y| 


14 


D S 


1 3 






£E 


3 7 


E M 


14 


E S 


5 4 






M £ 


2 6 


0 M 


25 


N S 


2 4 






IM £ 


5 7 






0 S 


1 4 






P £ 


2 3 


A N 


6 4 


i S 


35 






HE 


9 8 


E N 


ill 


R S 


3 1 






S t 


49 


1 N 


7 5 










T£ 


7 1 


0 N 


7 7 










-Vfe- 


5 7 


U N 


2 1 










W E 


2 2 




* 















ID : A64644 



Ti\BLE 9-D Continued. 



(2) AND ACCOrjJiNC TO THEIR ABSOLUTE FREQUENCIES. 



K A 


39 


0 F 


25 


i-l A 


36 


E F 


1 8 


E A 


35 






U A 


3 a 


N G 


2 7 


L A 


2 a 


1 G 


19 


T A 


2 8 






N A 


26 


T H 


7 8 


S A 


2 4 


S H 


2 6 


C A 


2 0 


G H 


2 0 


H A 


2.0 


C H 


14 


P A 


1 4 


T 1 


4 5 


E C 


3 2 


F 1 


3 9 


1 C 


2 2 


S 1 


34 


W C 


19 


H i 


3 3 


A C 


1 4 


N 1 


3 0 






R 1 


3 0 


E D 


6 0 


U 1 


2 7 


lv| D 


5 2 


E 1 


2 7 


A 0 


27 


L 1 


2 0 


K D 


17 


A 1 


1 T 


H E 


9 8 


A L 


3 2 


T E 


7 1 


E L 


2 9 


N E 


5 7 


L L 


2 7 


V E 


57 


1 L 


2 3 


S E 


4 9 


0 L 


19 


E E 


4 2 






L E 


37 


0 i'1 


25 


D E 


3 3 


A H 


14 


C £ 


3 2 


' E I'l 


14 


M E 


26 






P E 


2 3 


E IM 


111 


W E 


2 2 


0 N 


7 7 


H E 


2 0 


1 N 


7 5 


B E 


1 8 


A i'\l 


6 4 


G E 


1 4 


U t'i 


2 1 


1 E 


1 3 







T 0 


5 0 


N T 


8 2 


C 0 


4 1 


S T 


6 3 


1 U 


4 1 


A T 


4 7 


F 0 


4 0 


R T 


4 2 


R 0 


2 8 


E T 


3 7 


H 0 


2 0 


H T 


2 8 


W U 


1 9 


1 T 


2 7 


N U 


1 8 


0 T 


1 9 


P 0 


1 7 


T T 


1 9 


D 0 


1 6 


D T 


1 5 


S 0 


1 5 


Y T 


1 5 


L 0 


1 3 


C T 


1 4 


0 P 


2 5 


0 LJ 


3 7 


£ P 


2 0 


Q U 


1 5 






A U 


1 3 


E R 


8 7 






0 R 


6 4 


1 V 


2 5 


A R 


4 4 


E V 


2 0 


U R 


3 1 






1 H 


2 7 


T W 


3 6 


P R 


1 8 






H R 


1 7 


1 X 


1 5 


TR 


1 7 










T Y 


4 1 


E S 


5 4 






A S 


4 1 


Totnl - 


3745 


1 S 


35 






R S 


3 1 






N S 


2 4 






S S 


19 






T S 


1 9 






0 S 


1 4 






D S 


1 3 







TABLE 9-E 

;j.L THE 438 DIFFERENT DIGRAPHS OF TABLE 6 ARR.MIGED ALPE*V 
BF.TICALLY FIRST ACCORDING TO TflEIR ’’’INAL LETTERS AJJD THEN 
ACCORDING TO THEIR INITIAL LETTERS. 



(SEE T;_BLE 6. READ DOM THE COLbliNS) 



REF ID : A64644 

- 149 - 



lAJLE 10 A 

THE 56 TRIGBAPHS APPEALING 100 OR MORE TlilES 
Isr the'Bo,6oo letters of ‘GOVERUMENT PIAIH-TEXT telegrams 
. AH^GED ACCORDING TO THEIR ABSOLUTE FREQUENCIES 
! ' ■ • N 



feNT 


569 


FOU 


152 


ioN 


260 


CRT 


146 


iuJD 


228 


REE 


146 


ING 


226 


SIX 


146 


i:vB 


225 


ASH 


143 


ITIO 


221 


DAS 


140 


FOR 


218 


IGH 


140 


'OUR 


211 


ERE 


138 


'THI 


211 ■ 


COM 


136 


ONE 


210 


ATE 


135 


NIN 


207 


EIG 


135 


STO 


202 


FIV 


135 


EEN 


196 


MEN 


131 


GHT 


196 


SEV- 


131 


INE 


192 


ERS 


126 


TEN 


190 


UND 


125 


EVE 


177 


NET 


118 


EST 


176 


PER 


115 


TEE 


174 


STA 


115 


TOP 


174 


TER 


115 


NTH 


171 


EQU 


114 


TWE 


170 


RED 


113 


mvo 


163 


TED 


112 


ATI 


160 


ERI 


109 


THR 


158 


HIR 


106 


NTY 


157 


IRT 


105 


BEE 


153 


DBR 


101 


THEN 


153 


DRE 


100 



REF ID : A64644 



- ISO - 



TABLE 10 B 



THE 56 TRIGRAJES APPEARING 100 OR MORE TIMES 
IN THE 50,000 LETTERS OF GOVERNMENT PL.VIN-TBXT TELEGE^'iMS 
iUffiANGED FIRST ALHIABETIG/ 1 .LLY ACCORDING TO THEIR INITLIL LETTERS 
AND THEN ACCORDING TO THEIR ABSOLUTE FREQUENCIES 



AND 


228 


MEN 


131 


ATI 


160 






ASH 


143 


NIN 


207 


ATE 


135 


NTH 


171 






NTY 


157 


COM 


136 


NET 


118 


DAS 


140 


OUR 


211 


DER 


101 


ONE 


210 


DEE 


100 


CRT 


146 


ENT 


569 


PER 


115 


EEN 


196 






EVE 


177 


REE 


146 


EST 


176 


RED 


113 


ERE 


138 






EIG 


135 


STO 


202 


EES 


126 


SIX 


146 


EQU 


114 


SEV 


131 


ERI 


109 


STA 


115 


FOR 


218 


TIO 


221 


FOU 


152 


THI 


211 


FIV 


135 


TEE 


174 






TOP 


174 


GHT 


196 


TVVE 


170 






Tlf/O 


163 


HRE 


153 


THR 


158 


HIR 


106 


TER 


115 


TED 


112 


ION 


260 






ING 


226 


UND 


125 


IVE 


225 






INE 


192 


VEN 


190 


IGH 


140 






IRT 


105 


WEN 


153 



REF ID : A64644 



- 151 - 



•SABLE 10 C 

THE '56 TRIGRAFHS APPEARING 100 OR MORE TIMES 
IN THE 50,000 LETTERS OP GOVERNMENT PLAIN-TEXT TELEGRAMS 
ARRANGED FIRST ALPHABETICALLY ACCORDING TO THEIR CENTRAL LETTERS 
* AND THEN ACCORDING TO THEIR ABSOLUTE FREQUENCIES 



ms 


140 


ION 


260 






FOR 


218 


EEN 


196 


TOP 


174 


VBN 


190 


POU 


152 


TEE 


174 


COM 


156 


TON 


153 






REE 


146 


EQU 


114 


MEN 


131 






SEV 


131 


HRE 


153 


NET 


118 


ORT 


146 


PER 


115 


ERE 


138 


TER 


115 


ERS 


126 


RED 


113 


ERI 


109 


TED 


112 


IRT 


105 


DER 


101 


DRE 


100 


IGH 


140 


EST 


176 






ASH 


143 


THI 


211 






GET 


196 


STO 


202 


THR 


158 


NTH 


171 




ATI 


160 


TIO 


221 


NTY 


157 


NIN 


207 


ATE 


135 


SIX 


146 


STA 


115 


EIG 


135 


OUR 


211 


FIV 


135 




HIR 


106 


IVE 


225 


ENT 


569 


EVE 


177 


AND 


228 






ING 


226 


TWE 


170 


ONE 


210 


TITO 


163 


INE 


192 






UND 


125 







REF ID : A64644 



- 152 - 



I/iJLE 10 D 



THE 56 TRIGEAI^S /iPPETJlING 100 OR MORE TIMES 
IR THE 50,000 LETTERS OF GOVERNMEKT PL^IN-TEXI TELEGRAMS 
ARRANGED FIRST ALPHi'iJBETICi;jj:,y ACCORDING TO THEIR FIN/iI. LETTERS 
AND THEN ACCORDING TO THEIR ABSOLUTE FREQUENCIES 



STA 


115 


TIO 


221 






STO 


202 


Am 


228 


TWO 


163 


UND 


125 






RED 


113 


TOP 


174 


TED 


112 


FOR 


218 


IVE 


225 


OUR 


211 


ONE 


210 


THR 


158 


INE 


192 


PER 


115 


EVE 


177 


TER 


115 


TEE 


174 


HIR 


106 


TWE 


170 


DER 


101 


HRE 


153 






REE 


146 


DAS 


140 


ERE 


138 


ERS 


126 


ATE 


135 


ENT 


569 


DRE 


100 




GHT 


196 


ING 


226 


EST 


176 


EIG 


135 


ORT 


146 




NET 


118 


NTH 


171 


IRT 


105 


ASH 

IGH 


143 

140 


FOU 

EQU 


152 

114 


THI 


211 


FIV 


135 


ATI 


160 


SEV 


131 


ERI 


109 









KEF ID:A64644 



- 15S - 
11 A 

p 

THE 54 TETR/i.GEAPHS iJ>PEAilING 50 OR MORE TIMES 
.iS"T|ffi 56,000 LETTERS OF GOVERRlffiNT PIAIN-TEXT TEL^RAMS 
AEPJiJrGED ACCORDING TO TIIEIR ABSOLUTE FREQUENCIES 



TION 


218 


OMMA 


71 


EVEN 


168 


LUiE 


71 


TEEN 


163 


OLLA 


70 


EHTY 


161 


VENT 


70 


STOP 


154 


DOLL 


68 


TifENT 


153 


LARS 


68 




153 


THIS 


68 


TViEN 


152 


PERI 


67 


TiffiE 


149 


ERIO 


66 


POUR 


144 


ASHT 


64 


IGRT 


140 


HUND 


64 


FIVE 


135 


DRBD 


63 


UREE 


134 


RIOD 


63 


eIgS ' 


132 


IVED 


62 


li'iEH 


132 


ENTS 


62 


SEVE' 


121 


PEIC 


62 


ENTH 


114 


PROM 


59 


MENT 


111 


IRTY 


59 


THIR . 


104 


RTEE 


59 


EENT 


102 


UHDR 


59 


REQU 


98 


NilUG 


56 


HIRT 


97 


OURT 


56 


COMM 


93 


UGHT 


56 


QUES 


87 


STAT 


54 


UEST 


87 


AUGH 


52 


EQUE 


86 


CENT 


52 


NDRE 


77 


FICE 


50 



^ L. 



REF ID : A64644 



- 154 - 
OV^BLE 11 B 

THE 54 TETE/xGIL\PHS iiPPEfJlING 50 OR MORE TIIiES 
IN THE 60,000 LETTERS OF GOVERKlffiKT TIAIN-TEXT TELBGRAIIS 
iJJEi‘LNGED FIRST ALPHi^BETICilLLY *i.CCGRDING TO THEIR INITLIL LETTERS 
LM) THEN ACCORDING TO THEIR ABSOLUTE FREQUENCIES 



ASHT 


64 


AUGH 


52 


COMM 


93 


CENT 


52 


EASH 


132 


DOLL 


68 


DRED 


63 


EVEN 


168 


ENTY 


161 


EIGH 


132 


ENTK 


114 


EENT 


102 


EQUB 


86 


ERIO 


66 


ENTS 


62 


FOUR 


144 


FIVE 


135 


FFIC 


62 


FROM 


59 


FICE 


50 


hree 


134 


HIRT 


97 


HDND 


64 


IGHT 


140 


IVED 


62 


IRTY 


59 


LL-'Jl 


71 


UBS 


68 



MENT 


111 


NINE 


153 


HDRE 


. 77 


Nfi.UG 


56 


OMMtL 


71 


OLI^i. 


70 


OURT 


56 


FERI 


67 


QUBS 


87 


REQU 


98 


RIOD 


63 


RTEE 


59 


STOP 


154 


SEVE 


121 


STAT 


54 


TION 


218 


TEEN 


163 


ITJEN 


152 


TERE 


149 


THIR 


104 


THIS 


68 


UEST 


87 


UNDR 


59 


UGHT 


56 


VENT 


70 


TiENT 


153 



REF ID:A64644 



- 155 - 
O^YBLE 11 0 

IHE 54 TETRAGRiJ'HS /i.EPE^vRING 50 OR MORE TIMES 
IS THfe 50,000 LETTERS OP GOVERNLffiUT PIAIW-TEXT TELEGR/JS© 
jCiER^'jGED" FIRST ALmBETIG/i,LLY ACCORDING TO THEIR SECOND LETTERS 
' - AND THEN ACCORDING TO THEIR iiBSOLUTE FREQUENCIES 

- f. ... n 



aisH 


132 


OMWv 


71 


lARS 


68 






N/^UG 


56 


ENTY 


161 






ENTH 


114 


SpfiE 


77 


ENTS 


62 






UNDR 


59 


TEEN 


163 






WENT 


153 


FOUR 


144 


SEVE 


121 


COMM 


93 


MENT 


111 


DOLL 


68 


EENT 


102 






REQU 


98 


EQUE 


86 


BEST 


87 


HREE 


134 


VENT 


70 


ERIO 


66 


PERI 


67 


DRED 


63 


-CENT 


52 


FROM 


59 






IRTY 


59 


FFIC 


62 










ASHT 


64 


IGHT 


140 






UGHT 


56 


STOP 


154 






RTEE 


59 


THRE 


149 


ST/v-T 


54 


TEDi 


104 






THIS 


68 


QUES 


87 






HUND 


”64 


TiON 


218 


OURT 


56 


NINE 


153 


AUGH 


52 


FIVE 


135 






EIGH 


132 


EVEN 


168 


HIRT 


97 


IVBD 


62 


hlOD 


63 






FICE 


50 


TWEN 


152 


LIAR 


71 






OLIA 


70 







REF ID:A64644 



- 156 - 
T/iBLE 11 D 

THE 54 TETRA.GRAHHS xJPEi'iRING 50 OR MORE TIMES 
IN THE 50,000 LETTERS OF GOVERNMENT PLUN-TEXT TELEGRAMS 
ARR/iNGED FIRST ALEHA-BETIGAIiY ACCORDING TO THEIR THIRD LETTERS 
AND THEN ACCORDING TO THEIR i^SOLUTE FREQUENCIES 



LLi'iR 


71 


SLIT 


54 


FICE 


50 


DNDR 


59 


EVEN 


168 


TEEN 


163 


TWEN 


152 


HREE 


134 


QUES 


87 


DRED 


63 


rVED 


62 


RTEE 


59 


EIGH 


132 


AUGH 


52 


IGHT 


140 


ASHT 


64 


UGHT 


56 


THIR 


104 


THIS 


68 


ERIO 


66 


FFIC 


62 


OLLfi. 


70 


DOLL 


68 


COM! 


93 


OMMii 


71 



YIENT 


153 


NINE 


153 


KENT 


111 


EENT 


102 


VENT 


70 


HUND 


64 


CENT 


52 


TION 


218 


STOP 


154 


RIOD 


63 


PROM 


59 


REQU 


98 


THRE 


149 


HIRT 


97 


NDRE 


77 


LARS 


68 


PERI 


67 


OURT 


56 


DASH 


132 


UEST 


87 


ENTY 


161 


ENTH 


114 


ENTS 


62 


IRTY 


59 


FOUR 


144 


EQUE 


86 


NAUG 


56 


FIVE 


135 


SEVE 


121 



KEF ID:A64644 



- 157 - 
11 E 

THE 54 TETR'lGRAPHS /iPPB'iJlIKG 50 OR ilORE TIMES 
Ilf The 50,000 letters of gotErhment fu4.ik-text Telegr/jjs 
ARE i^IGED FIRST i\XHL-iREEiaVLLY ACCORDING TO TS^^IR FIN^J, LETTERS 
AND THEN ACCORDING TO THEIR /ilBSOLUTE FREQUENCIES 



cam 


71 


IION 


218 


QUA 


70' 


EVEN 


168 


— 




TEEN 


163 


_FFIC 


62 


TIVEN 


152 


HDHD 


64 


ERIO 


66 


DEED 


63 






RIOD 


63 


STOP 


154 


IVED 


62 










FOUR 


I44 


■NINE 


153 


THIR 


io4 


THRE 


149 


LU\R 


71 


FIVE 


135 


UHDR 


= 59 


HREE 


134 






■'SEVE 


121 


QUES 


"87 


EQUE 


86 


THIS 


68 


NDRE 


77 


luJRS 


68 


RTEE 


59 


ENTS 


62 


FICE 


50 










WENT 


153 


mvG 


56 


IGHT 


140 






.JvlENT 


111 


KxSH 


132 


EENT 


102 


EIGH 


132 


HIRT 


97 


BNTH 


114 


UEST 


87 


AUGH 


52 


VENT 


70 






. . . ASHT 


. ' 64 


PERI 


67 


UGHT 


56 






OURT 


56 


DOLL 


68 


STAT 


54 






CENT 


52 


com 


93 






FROM 


59 


REQU 


98 






ENTY 


161 






IRTY 


59 



REF ID : A64644 



- 158 - 
Ti»£LE 12 

j^VER.VGE yJilD MEAN LENGTHS OP YfORDS 

« 

No. of Letters No. of Times No. of 

In ?/ord Word Appears Letters 



1 


378 


378 


2 


973 


1946 


3 


1307 


3921 


4 


1635 


6540 


5 


1410 


7050 


6 


1143 


6858 


7 


1009 


7063 


8 


717 


5736 


9 


476 


4284 


10 


274 


2740 


11 


161 


1771 


12 


86 


1032 


13 


23 


299 


14 


23 


322 


15 


4 


60 



120 



9619 



50000 



5.2 Letters 
217 Letters 



(1) Mean Length sa ■■ 

9619 

(2) Average Length of messages . . 

( 3) Mean Length of messages ..... 191 Letters 

( 4 ) Mode (Most frequent) Length ... 105 - 114 Letters 

( 5 ) It is extremely unusual to find 5 consecutive letters without 
at least one vowel. 

(6) The average nvunber of letters between vowels is 2. 



***«*■»» 



KEF ID:A64644 



l|t :|c * 1|< I|< 3)< * iR >|C 4c >K lit ^ 



♦ 
* 
* 
* 
* 
* 

a|<:|c :)ci|<:ic ^ :tc 4c :)c :|c 4c i|c :|c i(i )|t :|i i|c 



INDEX 



REF XD^^64 644 

-xsiteQ^ 

INDEX 



r 


Page 


Paragraph 


Accented letters 


11 


i» 

5b 


Alphabets, bipartite 


» 73 


35c 


" , deciphering 


64 


31c 


" , direct standard 


2‘5,30,3S 


12a, 16, 19 


” , enciphering 


60,64 


29b, 31c 


" , keyword-nixed 


6S 


31d 


" , mixed 


S.'S, 30, 3y, 


12a,15a,19,21d, 




4R, '50,64 


2 2b, 24c, 31b 


" , reversed standard 


2'5,50,40,44 


12a, 16, 19b, 20b 


" - , standai'd 


2*5, 30, 3.3, 


12a, 15a, 16, 19, 


*' , systematically mixed 


44,49,80 


20b,23,3Se 


63 


31c, e 


Analytic key for cryptanalysis 


13,125 


6d,.50 


Arbitrary symbols 


27,121,122 


15h,47d,48 


Assimptions 


11.3 


46h 


Average length of messages 


23 


11b 


Baconian ' cipher 


74 


55e 


Bar distribution 


16 


9a 


Beginnings of messages ’ 


68 


32e 


Biliteral substitution 


35 


41 


Bipartite alphabet 


73 


3.5b, c 


Blanks, number of 


» 29 


14 e 


Book systems 


124 


49e 


Censorship, methods for evading 
Characteristic frequency of 


121 


47c 


the letters of a language 


17,28,51 


9d,14b,25 


Characteristic frequency of the letters 


•i 


of a language, suppression of 


77,37 


37,41f 


Checkerboard systems 


89,101 


44,45 


Checkerboards, 4-square 


> 89 


44 


Cipher, ' Baconian 


74 


35e 


’’ component 


70 


34 


” j distinguished from code 


79 


38c 


” text, length of as 






compared with plain text 


85 


40c 


" unit 


85 


41c 


Glassification of ciphers 


24,25,120,126 


12a, 13, 47, '0e,f 


Code systems 


10,88,120,122 


4a,41g,47b,4« 


” " , distinguished from cipher 79,. 'll 


38c , 24c , footnote 


Completing the plain component 


41,71 


20a, 54a 


Concealed messages 


120 


47c 


Condensed table of repetitions 


.57 


27i 


Consonants distinguished from vowels 


57,66 


23 , 32c 


" , relative frequency of 


20,25,33 


10a, 13, 19 


" , in succession 


66 


32c 


Conversion of cipher text 


46,47,72 


21a, c, 34c 


Coordinates on work sheet 


52 


26d 


Coordination of services 


7 


2e 



Paragraph 



REF ID:A64644 






- 160 - 



Page 



Greats and troughs 20 


,28 


,37,92 


10a,14b,41f,A4c 


" " " , absence ol' 




29 


14c 


Deciphering alphabets 




64 


31c 


Dictionary words used as code v/ords 




120 


47b 


Digraphic substitution 




86,83 


41c, 42, 43 


Digraphs, characteristic frequency 




■51 


25 


” , weighted according 








to relative frequency 




60 


29 


Distrj-bution, bar type 




16,23 


9-1, 11b 


" , normal 




32 


17b, c 


" , with no crests and troughs 




29 


14c 


Dummy letters 




121 


47c 


Elementary sounds, characteristic frequency 




23 


14b 


Enciphering alphabet 




64 


31c 


Endings of messages 




63 


32e 


Equivalent values 




31 


39b 


Figure ciphers 




27,122 


13h,48 


Fitting distribution to normal 


32 


,38,80 


17b,c,19,3Se 


Foreign language cryptograms 




11,15 


5b,7c 


Formulas 




69 


33d 


■•^’requfincy distribution 16,31,38 


,83 


,92,93 


9,17,19,26e,44c 


" ” i~- fitted to normal 




32 


17b, c 


" " . , for code 




120 


47b 


" ” , four part 




00 


38d 


” " , monoliteral 




16,51 


9,17 


" " , tri graphic 




54 


27 


" method of solution 


34 


,51,60 


18,24d,29 


General s'^lutions in cryptanalysis 




119 


46 i 


" . S/stem, determination of 10, 


12, 


25,125 


4a, 6, 13, 50 


Generatrix 




14 


20a 


Goodness of fit 




52 


17b 


Grilles 




121 


47c 


Hidden messages 




121 


47c 


High frequency consonants 




26 


13d 


Historical examples of polyliteral systems 




75 


36 


Idiomorphism 




70 


33e 


Indicators 




123 


49b 


Intelligence facilities 




6 


2e 


Intelligible text obtained by chance 




47 


21b 


Intuitive method 




68 


33 


Invisible writing 




1 


li 


Japanese Morse alphabet 




11,122 


5b, 43b 


Kata Kana Morse alphabet 




122 


48b 


Key phr-ase 




77 


36c 


Known sequences 




49 


23a 


Language employed in a cryptogram 




10 


4a, 5 


” frequency characteristics 




17, "1 


9d,25 


" • peculiarities 




11 


5b 



REF ID:A64644 



-xmxxx 

- 161 - 



Letters, accented 

” , lev/ frequency 

” j,, missing 

Loiv-frequency consonants 
Medium frequency consonants 
Messages, beginnings and endings 

amenable to cryptanalysis 
” , general phraseology 

” , hidden 

Military text 
Missing letters 
Mixed alphabet 
” sequence 
Modified Playfair 
Monoalphabets 

Monoalphabet distinguished from polyalphabet 
Monoliteral frequency distribution 
Morse alphabet, Japanese, Russian 
Normal distribution 
" frequency 

" " , deviations from 

Nulls 

New York Tribune 
Patterns 

Pentaliteral cipher 
Phraseology of messages 
Plain component, completion of 
Plain-text unit 
Playfair cipher 

" , modified 

Polyalphabotic cipher distinguished 
from monoalphabot 
Polygraphic substitution 
Polyliteral substd tution 

systems, historical examples of 
Prefixes in trigra.phic distribution 
Prerequisites for cryptograpliic work 
Probable-word method 
Pseudo-po^lygraphic systems 
Punctuation in telegraphic text 
Random text, number of blanks 
Relative frequencies 



Pago 

11 

64 

11,29 

26,64 

26 



■ Repetitions 



, in a code message 
, of consonants 
, of digraphs and trigraphs 
, condensed table of 



68 

125 

121 

21 

11,29 

50,48,50,64 

48 

106 

1 

24,28 
16,51 
11,122 
52 

17,21,51 
26 

85,121 
75 
69 

74 
125 

41 
85 

94,102 
106 

24.28 
85 

75,77,85 

75 
56 

2 

68 

87 

21 

29 

21.28 
27,50,51,56 

79 

66 

56 

57 



Paragraph 

5b 

51c 

5b,14e 
15d,31c 
13d I 

32e 

49a 

47c 

10b 

5b,14e 

15a, 22b, 24c, 51b 
21d 
46d 
lb 

12,14 
9,17 
5b, 48b 
17b, c 
9,11,26 
13b 
40,47c 
36 
35d 
35e 
49a 
20a 
41c 
44,46 
46d 

• 12,14 
41 

35,37,41c 

36 

27e 

2 

35 

41e 

10c 

14f 

10b,c,d,ll,14b 

13g,24b,24c,27 

38c 

32c 

27f 

27i 



II 



REF ID : A64644 

-x}iiSEax 

- 162 - 

Pago Paragraph 



Reversed standard alphabets 


30, 


16,20b 


Reversible digraphs indicated on T/orksheet 55 


26f 


Russian Morse alphabet 
Secuajity of monoalphabct using 


11,122 


5b, 48b 


standard alphabets 


49 


23 


Sequences, known 


49 


23a 


" , mixed 


48 


21d 


" , unknorm. 


49 


23a 


Solutions of a subjective natxjro 


8 


3 


Specific key 


10,14,40,64 


4, 7, 19a, 31b 


Standard alphabets 


50,44,80 


15a,16,20b,38o 


Subjective solutions 


8 


3 


Substitution, bi] iteral 


85 


41 


” , digraphic 

" , distinguished from 


86,88 


41c, 42a 


transposition 


24,25 


12,15 


" , polygraphic 


85 


41c 


” , polyliteral 


35 


41c 


" , trigraphic 


• 85 


41c 


" , triliteral 


85 


41 


Suffixes in trigraphic distribution 


55 


27e 


Suppression of frequency 


77,84,87 


37,40b,41f 


Symbols as cipher elements 


27,121,122 


13h,47d,48 


Telegrams, average length of 


23 


11b 


Terminology 


1 


1 


Text, different tsTics 
Transposition distinguished from 


21 


10b, c 


substitution 


24,25 


12,13 


Trigraphic cipher system 


85 


41c 


" frequency t-iblo 


54 


27 


Triliteral freqTxency distribution 


54 


27 


” substitution 


85 


41 


Typo numbers for cryptographic systems 


126 


50f 


Unknown sequences 


49 


23a 


Variants 


78,84,123,124 


37d,40b,49c,d,49f 


Vov/els, average distance apart 


66 


32c, footnote 


" , combinations with consonants 


57,58 


28,29 


" , " ” vo;vels 


59 


29a 


" , distinguished from consonants 


57,66 


28,32c 


" , in succession 


66 


32c 


" , relative frequency oC 


20,25,38 


10a, 13, 19 


Word formulas 


69 


33d 


” lengtlis in a cryptogram 


52,68,69,70 


26c , 32e , 35d, 33f , g 


” patterns 


69 


33d 


" skeletons 


61,68 


30b, 32o 


Work sheet, preparation of 


51 

(1 


26 




NUMBETR or 







iiiiffii 

irraiiiBiai 
" " iniisi 



a- r ill 



iMiiiiHil 

i minijl 

tiinliil 



ilsniillliililll 



iHiaii 

aiuail 






laiiBL. 

liIHRII 



IBUiniMIIIHI 



■I*' J'*'i lurliiiiiinl 

IB 

EMI ■■Mlig 

I It <r iiKHlI 
•^riaii!ii 




aiiiip 

fipiiBiimH 

BlnmiH 

pisiiijiiia 

linnii 



imi 



Miri •ir itf IH! 

Hamr*' raasBiB iiiiiiiMi Maiiiai 

lunilirr 

I iM'wsiiar 

tfaar Fnaitj 

iruMpnin im 

II iit*rTMi„„. 

I hRlP HI 



S iaiaHnuiii 
uygaai 
iiiifflEir 



Slfliilll 

iimar 

S -mm 

larai 



PHSHl 

iiKi 

Bnir' 

aai 



ins: 

IHI[ 

__ 

BH 

mmmm 
Biisai 

___ jiiisiisai 

j-iilil 

nium 

naiSIKii 
nmaHi 

iBiaiBn 

msnaii 



iBieiiiiiMig 



igaiHi! 



ms 

'■ r- 



II!ll6iyL_. 
IHWIHIIilll 






aimii!;i 



111 



uji Trfgi 
iB I lallr I lii 

fevir!. 

rp rr» riiisnii 
■ iij 1 iBBii 

"fmm 

ill JUki jELmauiia 

I r iiijj j'laart'i 
■iriilv lanii I 

irrw' 

I r lU ^ . 

|r Hi aim 



Inmuiiil 



f waililKuiii 
WHiiHiiill! 
BHHIigllllll 

ItlllWIIIIH 



II Jb» 

8 "■►■'Pi. “ 

■I I llll Tr 
n JPI"' .. 

HiHitaiuwBaiii 

iDMiiiiaaigiai 






i'ja 



Pb-lul 



1 p B 



S EKsmiil'n £4 ■ IBBIiilt... 
Hsnilav riiPiP ibbb9!i 



ilBBH 



'■■r ■ 



mengjiis 



*1 



_.__:isiiisiii 

HUBianpii 

■gnaii 

la—B 



94P' 

HI I f "Q 
Hill 



IBBiH 

IKSKBinilltl 

satsssirdl 



IPIIB! 
lygg! 
iHlSSI 

laasiiiial 

•wz 

iiii 
Ejssniiii 
al S iBliBii 



iiliilii 

iSlilll 



mm 



rr 



IPUBBi 



lBignsi?H»*iii 

HSieiMa 

laiiiipe 

IHIIIIIL 



r.E 



llllIMHiiaBilldiill 

■Biiejisiiiiiiiiisliiiiii — 

■“liS!Sll|!ilM|ilB!!llir 

■riHiHHI! 

■iinBiiil 



aBumuii 



iny 
-jjsui 



JBHBainBnU|HBII01ijia!HIH|l3liB]BII!}lll31i 

— liiiaiMW BBB iiMaiigiiH 

iisBBBliiiLBiiiawImMiiBDilB 

— IniiiiiiBBiHiiiiiHilniKa 

■i mUB MiMItlMMIMMaiWIBilimifllll 

HnifinangnliiaBiiiHmiaflEuu 

lUBHBPIIUIIISilSBillliWail 



IHIIBIjSlI 



qiHi 



lienaip 



R"! ' HI 



Inn ■' 



mainl 

liliiilliBiHiliilBil 

a BlMStl 

BemiiiiiL ^ 

jpiiffliiiiiiiKKilsii 

■Bl DBI PH" IHjr 

IL JB — iii li irbii jB iiiiiiiaiiliiilllliM 

riiSMSi isr 'Pir ^Miii 

al ■' liruiBSiti n ji3iiii|glai»iHaiuiii;^J lui I fii'iPiiiiBiiiiaB' 



'f'f 



■ jiiraei 
iiniiin 

HHIHir~~ 

imaii 

iisyiiijiiui 
ISfiSiS 

mggii 

J iBSlijiir 

llBiilliL 

massinipn 



^gsBii 

biuiihI 

JI M WHaBI 

i!iiiiiliEiiai~ 

^■HHI 

-JHilBL 

mjjSffljr" 
HSIiHiy 



msi 

•m 

DHIU 






nan 

iiii" 



WyilMBnl r Hlr 

K Pbiilil ' .iHlf a '.i 

lyHipytiiiiiiijiiiwiiwsiHiyi 
aiMEii'i:.:9NjiiiiKaibiJi 
ipii!i!iiniainisiHliiii!i riiiymiiiiin 

iHiwiiiiiiipiiiilliyiiui -.ri 

iBaaai MiB faa HiiiaiH i . ^<.i|iri 
iHiigpiBiSiKiiviioHiii laiJ^L' B ^ ■ , 

IBfrjBB'ja'B'ilIT? 

sag ill- iiuip^iiiiiiaii 

MWIgjlil lllilH Blliia- _ 

■I '.■TBJlIll'a i.V ■ ■■ j P'Dr*. E 

■piaiDignHa jpB„:iia 

linnKBiiiiiiiiiiBiiGiriiiCypyaix i iuyniiiiyna 



KDH'ISIflEnp^ 

yui^iuuiiSHm 

IHffllRIIlillit 

"^ilWIHIlgiSI 

iniiaBiiiii 
iBiiiiaaiii 
lEwymiiieiii 

IBai 

“■■llpfflllSIl 



imuiii 

IHIIIillll 



a lllla'’^ '"''i 9 ' 
'■r." a aVWKI«" r- 

BnuiniiinirnBi sssij'ucii insiiiiiioiiHiQiiLaiB 

iilEasB'BHWK 
liirjr-*-: rjiitijpaip'* -s 
I.JHi'i^'' .i .1 1 jtd 

B"ll JtHBiBP'p-aJililll 

p''yg4iii:ypBi[lia'Firriiypiti iijl 

«»'> 'MInTHL"' ■ j j. 

■ pill" iiBiiiiianiiiiiiiiii 

Hi'" laiiiiMs 
r-Bii'iBgipi^iil 
''*»iaaBiEmii!iri| 
ft BBJIBlIlllipPja ■ 

'IBEIlJ ■ 



'“'■frj 



■ - ■ !|ep»|iis 

Ip'.ik j 



BaaBi 

mi — 
Hi 



IISi 



Huai 



HBIHIHIbi if r 

IPB All J 
Eapnir 
ui'pnc. 



llil 

fflil 



II 

__ JPIIffiff 

••^^tana iii iiMBajaigiisiii 

kj'i JiJiPea’ 

i Miia ppbiBgiiaiiiiiiipiiiiiniaiis! 

iipili'kr! vr' 

■ ijpsriH 

liilpiia ai il a i B fHaBti iPHS 

ntncnEfir r iHiBffiSBi!i!i!!iiii« 

Jius: SliNM 

iiisaaBirraHi7';sii 

^BHin’—DiirB" rai 

BMSigiliiiliHiiaililBil 
iMB MilB ISItllMMI 

lagigiH-' "I 



yunin 



MBHV 



Mill 



1 -Ji! 



JB'*I 

iirH> 



Diiimian 



liP4 i 



f i luni 

WBHBBIWE3Sill 



igiHi 

Ibbs 



SpeiHH! 

Hsniii 



■iiioga ia iiii 



rum 

jaiiiiii 

rnmmmtai 



JIIBMIBI 

lili I ■I'llfi Ik ] 

l|H»!!!l V %rm t I 

mi * tt" ■■ 

IBiL ir 4 IJL I 



-'"mBiil 

■rti ipr mur 

IImSIIIII riaililiiji 

jr 

ii 



IBBBIHI 

iBiiHipsaf,™ 

IHIPliillllBl 

BBHIHIiipilIRgi 

JBBSillliHlsii 

BiMUi)iiUiiBii i amiaBB«Mg *i i uwj|p < i itai 
«'^minilumimiiH!SiiiiiDnEiiiiBii!si B-eniih 
giBHBBmaBiaHmBlaBii MB fflgf n aiBiHU! 

isiiiDppmfnBOiii!iaEriMpBii!iiiiiiii ir irdiiiiiBi 
iiiiPiinBaiHiiiiiiiiiiSiiiuKiiiyyii ■ apiiiiHul 

iBiiiPSuiiitiHwlllilBiiaiiiiiwEEFiKytM 



Mrs 






!ii!! 4* liilimi 

miiiijiiii If 

pk> ■lamna p 

iniPiHiiiiilif r 



M HiU MirrtillUHP IIIlB 

Pi»a ifUin 

w E a 1 



lEj J^J ii?*J 

niiihHiiS riB ami>i<iMDiiaiJlli 

PBRiniBUPlieBUlHIHIUPPKI 

J Jl SlkBJu 



a !■ 

iimiMiai 



aHUHiuuMiwa m m m Hi's 

inniBip n I r Bii 
■l«jl Br li fJTMWin 



M n I u/ I rMvgBp irir.iap:! rni.BEdP 
I IB iBl KiilB>-iaii p ^iHiiili l iiM ! ffi B «iniii«ei!i 
wu 4* m- raf' tr ■ aTkt. unnieiiiiiipaHnr' 

llfpaia LBf dilllllri'l kllJ 1 IlflUiiB^U 1 

ndBainiB jii„ 1 " nriB bbijj Jdvi 'iji'i ir 
•HSiimaBilPllillKl IBB «H_I B.ll..iJBli IP 



——■Hmnuiui 

iBnaiiiiBr 






liiiiji 

.._jiiBaiiaKBiiHBiQcw!miiSiBBiJlf ii u iOli 
—JliBiHiyiBi •ip'rjifg jggppiniiiiiimp p m i 

Bin J ■d-’liMLJUBBiilWaBai 

l■lfr .iHaingnpnBBiiiir 

Hp. j. I Bii MlUniliii iiaSgipl 



PH ■BamiiimiMijiMismlimMism 
E IB«BilipSBRS»lHiB!«!<nmimiHIISII 

iri amiiiwpmiiiGiiymwapimiifiHiiitiiijii 
>1.1 piHiiP •‘iiniiiiiiMiBiiiiWianfliir 



PJBJJJ kUlUJ 



pnniiiiRjgi 

lyimaiiiilii 

Hifaaiufi 

umimigiwi 

IB!!l{jlllBiCr~ 

SnSIlfBl 



HBMI 
UBiaiBSI 

liKnBi 

IlffliliBI 
IIHiai!li!l 



raiiii 

rH^I' m 



sr 



Ima: 



sai 

aai 



MSCB 

laiBiiiia 



P!bri‘3iiiiii jlHSItrillKi 
KBiiiiii E ciaipmiiwii 

■ r.Hinai-iBiiii'1:: ill 

.. .. WHiiiiiiEiaigiiiiiBiiHi 

ns aU illF|nsinn!iiSlliBlii91il!lil 
' :'=jBi!'!;i^!..jLJ[ie.:.kJaii:i;r...... 



iCaiiii 

llMSilS 



_ rri 

lai UITIX I 

■luyniii.* Ji imfilBspi 
DRHIBUjHBa J 1 MililMyr'-' 

IpnJilflkiiiEliiiikakiiiklilRII 



IBBl 

iBimi 

isr^ 

ir 



lUiMi 



ll'iri ilBllI''''' H.h 



BHili 

IBl -pBa -r ■ n ■ ■ IjB ■ ■■ ■ e -ejbt r l b *p-. m ‘ 

IP . .i.ij;jiii!i ■» ''' ' ' t .. .lui]' > .j'nEIb ii. ,.b 

■ Ha :i ri-r.J..kAi.\g,l|.|>- 



rickip t ' 



dK*- 

B SSSSSif 

wiapmmi 
BBBiiliiimispnmi 

pigiismipiip 

liFIL'in .■aiilBB 

ib!t; w 
TsapRr'/jfB7:r 
rrjij ;ii 

•IB'!'- "^.r.ii 

^ BBliF'kk i..i 

5- J" ■ a'kl 

kF - > I 

iiilnan»iiiini B iB B l]iiPI 
niPBiMipiiigilBBsis^^ 

irmiitiiBii<iii!!mns!n!i!| 

K HiRSHii wiHimK nBBiMimiiBP'Bgiiiiiy'i'Sijiiiaiiiiiff 

~ pmniiilgiiiaisanBgi e 

-JfunniiliRMaiiiiBillhj.-j; .^sgnunjitiii 
■ - rii :tbmEib e , s * . ■ s „ i- ikiihir' ' l 

KiiwiiaiiminiiB ' .* kninm prn'j|kniniiik»"t!ai' b| 

iilH''! 

g BPBiapgipyi'jyBiimBnBsnBniiiiiiii!! 
P'lBrsBiiiilni"''. ,.j ml-. £ -!j dByimniflyl. 

9'dfl .PP!" n ■■ ii"'! N-i-iB 

iJHl! '' 'i 1,,,..- i'll ?!► 

M'SmllPIBPri. J*-i|S-,==.f-„-.llvl. ai 

-liilsiaiji - 



to 15 20 85 30 35 40 ^ 50 55 00 05 70 75 ao 66 »0 96 IQO lOS 110 ItS QO (25 tSO OS 140 t4S ISO 155 (30 105 110 ITS 180 IQS t90 195 600 
NUMBER OF LETTERS PER MESSAGE. MILUMETERS 

ii«»a 






>11^ 



lir#ir;i=ilr 



REF ID: A 64644 



■r -n«rr ' 1^3 






liiiiiiiiMliliiiiiiainiiiiH 



IISII 20 



I 9 I 99 I 



1 



iinijeiii 



ammi 






-llii 

BT 



HSdOliO 



IIBIBL- 
aj»BllBi 



Bli 



Pil 

timli 



IHBU 




lillSi 

litiiii 



D!B£I(II 

■aeii 

I!H| 



’ s 3 sm 



— ^PHMMii iiilaiiiia 



JlHi 

isaiimBiyiiiiiii 

IRiiloiSlll 



IlHIii 

lipB 



Silf" 



nataii 



BiaaBiiiBaiiMHi 



iBaMMiaaBgpisiiiMMiMBaiMaiai 



iilBiiilnisBL.. 

8 Kgie» 



imi 



1119 



iSiaMgiiiBiiMEiiBiiiiiiaeg^.^iiiMEiiM Eigiiaaiii 



■aiiil 




\ m ^ m \ 



|!»| 



laiiSE 



Isiaiil 



llileisa 

"isiiiBr- 




i ll 

mi 



IliHljllilPll^ 




UH llW Iiili 
BBiiluillillll 
9111 



yil 



^nawspia 




BsaeiEisi 

-Hill! 



BiiBI 




lEI! 



RBS 

liSIG 




ii 8 illik!ini 9 »ii 



RiUBI 

iHiai 



Ena 



HSWI 



'B 




EBUfi 



iaaia a 



pie 

iias 

Killlllt 

■HI 

iffltr' 

Hi 



Big 



HU 

HBi 



Bimeii 

ji^ 



illF 



I9B 



isaiiiEiHi 



iHBli! 



IlHS 



!S]ISllilRi 

RBStieiiiliaiil 



BBSS 



iRWB 



Iffl'iSIL, 

IKIiliHl 



SHI 



Bi 

■dliliiSLHJIt 

BglgBBr 

iniiiinniHBiiniL„ 

BIHinililUlHail 



iEEuniiii 

teUBSL 

eHiHlP 



IIF 



S HlI 

ml 



■111 



BHBii 

le'iiil 



Bna 



iiisa 




■■ME 

iiawa 



■inu^ 

EliSHr 



anoniBi 



HHIHS 



H J3S 

lliuta 




aiaiPiBaaKiii^MiiiiiagiUiiiuagBisgasaigBagisgiMBaiBM 



iHlii 



■BBaBa m iiai 



IlH 






Bgaiiiagii 



BB 



Hliiliitiil 



inniiis; 

iKHa 




'MlHill 

inilliiiB whI 



liisiyli 



pai 




pufliiaiH 

lUiHar 




iinsiiRisKiHl 

\ m ^\ 




iHSiHl 



9 HI 9 SBHI 






PHI 

IHiPBliBI 



liyjjlll 



BUS 



liHBiia 

iiKiiiiiismS 



isioiiia'iiii 



lii 

SiHBUHil 



iniHB 



psl 

IsjiH 

gHHliilHlI 



UIHilliBI 

■■sHir 

gsnir 



5 10 15 20 25 30 35 40 45 50 55 00 05 70 75 00 S5 90 95 100 105 UO H5 120 (25 130 135 WO »45 J50 155 160 105 170 175 ISO 195 190 J95 200 

NUMBER OF LETTERS PER ivlESSAGE M)LL1MFTER«; 



MILLIMETERS 

No 336 







REF ID:Afe4644 









^ lllill^ilKa3S.niiii£ilRiiisaiLiili£ 

un|i|n*ii^ iinr r • I'j |L Ik. 3 ,r j | \* up >dinL« < _ : ipt ss iph-^ . . 



NiSijpfailMial 

KniiitnRinnitrT 



iaaimBMiBisiMiBiiiiiiiiiijffiiiiiiiiiHiwiiiiiMaiiiaMPiililMiiiiiiim 




iTiieiiaiiiiiipill 



sisiliiiiiiiiiiiiiiiilanin 






ligiiil 

limii 

juainiiai 
iBaiH iiiiia lni 
iniiappaiiiesi 

SIEi 

■UliBiili 



HSSSKISISKH 

pa^Eiiis 

liaiifiiiaaaH 

laiiiiiMiiiiiaaiHiiaigr 

g aBil Biiiliiiiiiii!-- 

■iiaiaHiiaiBiiair 
BilBlBr 




jaiimaijisiiaiBiiHliiiiilliiiignasiiiiili^ 



■pianaBugripiri^ipip 

aiiiKaiK 

ISiHIBIinilDllliBlIiSB 

mm 



BiinpanpiiiiiiiGapjiaRapin 



laaTiiiiiiiHRraBBBaiiaBiBjiiaiiir'' 

inaiHiDBir 




IsiBiaL.. 
mwinipnijM 

S HiBIHii — 

maaei 
saBinRi 




iniuiBBaiii 







5 10 15 SO a? X 35 <40 45 50 65 ■ 60 65 70 7 5 60 6 5 90 95 lOO 105 110 116 ISO 125 BO (35 140 145 150 155 160 165 (70 175 160 185 190 195 SOO 

number of betters per message. millimeters 



BiyaiiMiPaiipBiBMii ii aiSBr^ 

laiuiiiiaaieiuiiBipiiisi 

mil 





lUTiii 
lliBii 

iBROWIillllllWiDli 
— liuaanBiiiiiiiii 

Mii ia iiiaiBisaa 

IffiilHESPinilSIiRli 

HBUlHIliaKBillii 




